CVE-2026-28458 | OpenClaw up to 2026.2.0 WebSocket Endpoint /cdp missing authentication (GHSA-mr32-vwc2-5j6h)
A vulnerability has been found in OpenClaw up to 2026.2.0 and classified as critical. Impacted is an unknown function of the file /cdp of the component WebSocket Endpoint. This manipulation causes missing authentication.
This vulnerability is tracked as CVE-2026-28458. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.