{"api_version":"1","generated_at":"2026-04-11T20:39:51+00:00","cve":"CVE-2026-3691","urls":{"html":"https://cve.report/CVE-2026-3691","api":"https://cve.report/api/cve/CVE-2026-3691.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-3691","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-3691"},"summary":{"title":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerability","description":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that the target must initiate an OAuth authorization flow.\n\nThe specific flaw exists within the implementation of OAuth authorization. The issue results from the exposure of sensitive data in the authorization URL query string. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-29381.","state":"PUBLISHED","assigner":"zdi","published_at":"2026-04-11 01:16:16","updated_at":"2026-04-11 01:16:16"},"problem_types":["CWE-200","CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":[{"version":"3.0","source":"zdi-disclosures@trendmicro.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.0","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.0"}}],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-229/","name":"https://www.zerodayinitiative.com/advisories/ZDI-26-229/","refsource":"zdi-disclosures@trendmicro.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-6g25-pc82-vfwp","name":"https://github.com/openclaw/openclaw/security/advisories/GHSA-6g25-pc82-vfwp","refsource":"zdi-disclosures@trendmicro.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-3691","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3691","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"OpenClaw","product":"OpenClaw","version":"affected 2026.2.21","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","product":"OpenClaw","vendor":"OpenClaw","versions":[{"status":"affected","version":"2026.2.21"}]}],"dateAssigned":"2026-03-07T01:53:32.004Z","datePublic":"2026-03-30T13:21:56.169Z","descriptions":[{"lang":"en","value":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that the target must initiate an OAuth authorization flow.\n\nThe specific flaw exists within the implementation of OAuth authorization. The issue results from the exposure of sensitive data in the authorization URL query string. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-29381."}],"metrics":[{"cvssV3_0":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.0"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-11T00:17:40.509Z","orgId":"99f1926a-a320-47d8-bbb5-42feb611262e","shortName":"zdi"},"references":[{"name":"ZDI-26-229","tags":["x_research-advisory"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-229/"},{"name":"vendor-provided URL","tags":["vendor-advisory"],"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-6g25-pc82-vfwp"}],"source":{"lang":"en","value":"Peter Girnus (@gothburz), Demeng Chen (@DemengChen233), Project AESIR with TrendAI Zero Day Initiative"},"title":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerability"}},"cveMetadata":{"assignerOrgId":"99f1926a-a320-47d8-bbb5-42feb611262e","assignerShortName":"zdi","cveId":"CVE-2026-3691","datePublished":"2026-04-11T00:17:40.509Z","dateReserved":"2026-03-07T01:53:31.937Z","dateUpdated":"2026-04-11T00:17:40.509Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-04-11 01:16:16","lastModifiedDate":"2026-04-11 01:16:16","problem_types":["CWE-200","CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":{"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"3691","Ordinal":"1","Title":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerabili","CVE":"CVE-2026-3691","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"3691","Ordinal":"1","NoteData":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that the target must initiate an OAuth authorization flow.\n\nThe specific flaw exists within the implementation of OAuth authorization. The issue results from the exposure of sensitive data in the authorization URL query string. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-29381.","Type":"Description","Title":"OpenClaw Client PKCE Verifier Information Disclosure Vulnerabili"}]}}}