HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-34503 — OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when dev...
Tuesday, March 31, 2026 at 03:16 PM UTC·Source: NIST NVD
Updated: Monday, April 6, 2026 at 02:17 AM UTC
Executive Summary
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.
Analysis
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection. CVSS Score: 8.1. Published: 2026-03-31T15:16:19.470.