PT-2026-57888 · Openclaw · Openclaw
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.6.8
Description
An authorization bypass exists in OpenAI-compatible HTTP model overrides. This issue allows callers with lower trust levels to perform actions that typically require stronger authorization checks. Attackers can leverage misconfigured input paths to bypass admin authorization policies and execute restricted operations.
Recommendations
Update OpenClaw to version 2026.6.8 or later.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw