PT-2026-26733 · Openclaw · Openclaw
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.1
Description
An authorization mismatch exists that allows authenticated callers with
operator.write scope to invoke owner-only tool surfaces, including gateway and cron, through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level due to inconsistent owner-only gating during agent execution.Recommendations
Update OpenClaw to version 2026.3.1 or later.
Exploit
Fix
Missing Authorization
Improper Privilege Management
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw