Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key →
← Back to dashboard
clawsmith.com/signal/cve-2026-41299-acp-provenance-bypass-websocket
IssueWide OpensecurityLive

CVE-2026-41299: Gateway ACP Provenance Guard Bypassed by WebSocket Client Identity Spoofing

OpenClaw before 2026.3.28 allows authenticated operator clients to spoof ACP identity labels and inject reserved provenance fields via manipulated WebSocket handshake metadata, bypassing authorization (CVSS 7.1).

Score Breakdown

Issues
7

Frequently Asked Questions