📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 37m Global general Technology / Consumer Protection MEDIUM 48m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 37m Global general Technology / Consumer Protection MEDIUM 48m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 37m Global general Technology / Consumer Protection MEDIUM 48m Global vulnerability Information Technology and Security CRITICAL 56m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2026-32045

Medium
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networ
CWE-290 — Weakness Type
Published: Mar 21, 2026  ·  Modified: Mar 23, 2026  ·  Source: NVD
CVSS v3
5.9
🔗 NVD Official
📄 Description (English)

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to access HTTP gateway routes without proper authentication credentials.

🤖 AI Executive Summary

OpenClaw versions before 2026.2.21 contain an authentication bypass vulnerability in HTTP gateway routes due to improper application of Tailscale header authentication. Attackers on trusted networks can access protected routes without valid credentials. While no public exploit exists and patches are unavailable, this vulnerability poses a moderate risk to organizations using OpenClaw in network gateway deployments, particularly those relying on Tailscale for network segmentation.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 16:19
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily affects Saudi organizations using OpenClaw for network gateway and API management, particularly in: (1) Banking and Financial Services (SAMA-regulated entities) relying on Tailscale for secure network access to payment systems and APIs; (2) Government agencies (NCA oversight) using OpenClaw for internal service routing; (3) Telecommunications providers (STC, Mobily) managing internal API gateways; (4) Energy sector (ARAMCO, utilities) with OpenClaw deployments for operational technology network segmentation. The impact is limited to attackers already on trusted networks, reducing immediate risk but requiring urgent remediation for organizations with sensitive internal services exposed through OpenClaw.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare Technology and IT Services
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Audit all OpenClaw deployments to identify HTTP gateway routes currently using Tailscale header authentication
2. Review access logs for suspicious authentication patterns or unauthorized access attempts to gateway routes
3. Verify network segmentation and confirm which users/systems have access to trusted networks where OpenClaw is deployed

Compensating Controls (until patch available):
1. Implement additional authentication layer: enforce token-based authentication at application level, independent of OpenClaw gateway configuration
2. Network segmentation: restrict access to OpenClaw HTTP gateway routes to specific IP ranges or VPN endpoints using firewall rules
3. Disable tokenless Tailscale header authentication: configure OpenClaw to require explicit token validation for all HTTP gateway routes
4. Enable request logging and monitoring: log all HTTP gateway access attempts with source IP, headers, and authentication status
5. Implement WAF rules to validate authentication headers before requests reach OpenClaw

Detection Rules:
1. Alert on HTTP requests to OpenClaw gateway routes with missing or invalid authentication tokens
2. Monitor for repeated failed authentication attempts followed by successful access
3. Flag requests with Tailscale headers but no corresponding token validation
4. Track access to sensitive gateway routes from unexpected source IPs within trusted networks

Patching:
1. Subscribe to OpenClaw security advisories for patch availability
2. Prepare upgrade plan to version 2026.2.21 or later once available
3. Test patches in non-production environment before deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع نشرات OpenClaw لتحديد مسارات بوابة HTTP التي تستخدم حالياً مصادقة رأس Tailscale
2. مراجعة سجلات الوصول للبحث عن أنماط مصادقة مريبة أو محاولات وصول غير مصرح بها إلى مسارات البوابة
3. التحقق من تقسيم الشبكة والتأكد من المستخدمين/الأنظمة التي لديها إمكانية الوصول إلى الشبكات الموثوقة

الضوابط البديلة (حتى توفر التصحيح):
1. تنفيذ طبقة مصادقة إضافية: فرض مصادقة قائمة على الرموز على مستوى التطبيق، بشكل مستقل عن تكوين بوابة OpenClaw
2. تقسيم الشبكة: تقييد الوصول إلى مسارات بوابة HTTP في OpenClaw إلى نطاقات IP محددة أو نقاط نهاية VPN باستخدام قواعد جدار الحماية
3. تعطيل مصادقة رأس Tailscale بدون رموز: تكوين OpenClaw لفرض التحقق من الرموز الصريحة لجميع مسارات بوابة HTTP
4. تفعيل تسجيل المراقبة: تسجيل جميع محاولات الوصول إلى بوابة HTTP مع عنوان IP المصدر والرؤوس وحالة المصادقة
5. تنفيذ قواعد WAF للتحقق من رؤوس المصادقة قبل وصول الطلبات إلى OpenClaw

قواعد الكشف:
1. تنبيهات على طلبات HTTP إلى مسارات بوابة OpenClaw بدون رموز مصادقة صحيحة أو مفقودة
2. مراقبة محاولات المصادقة الفاشلة المتكررة متبوعة بوصول ناجح
3. وضع علامة على الطلبات برؤوس Tailscale بدون التحقق من الرموز المقابلة
4. تتبع الوصول إلى مسارات البوابة الحساسة من عناوين IP غير متوقعة ضمن الشبكات الموثوقة

التصحيح:
1. الاشتراك في تنبيهات أمان OpenClaw لتوفر التصحيحات
2. تحضير خطة الترقية إلى الإصدار 2026.2.21 أو أحدث عند توفره
3. اختبار التصحيحات في بيئة غير الإنتاج قبل النشر
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.9.2.1 - User access management and authentication controls ECC 2024 A.9.4.3 - Password management systems ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.13.1.3 - Segregation of networks
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Software, platforms, and applications inventory SAMA CSF PR.AC-1 - Access control policy and procedures SAMA CSF PR.AC-2 - Physical and logical access controls SAMA CSF DE.CM-1 - Network monitoring and detection
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access control ISO 27001:2022 A.8.2 - User endpoint devices ISO 27001:2022 A.8.3 - User access management ISO 27001:2022 A.9.2 - User access management
🟣 PCI DSS v4.0.1
PCI DSS 2.1 - Default security parameters PCI DSS 6.2 - Security patches and updates PCI DSS 7.1 - Limit access to system components PCI DSS 8.2 - User authentication and password management
📊 CVSS Score
5.9
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityH — High
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.9
CWECWE-290
Exploit No
Patch ✗ No
Published 2026-03-21
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-290
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.