PT-2026-99224 · Openclaw · Openclaw
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.7.1
Description
The software fails to enforce the administrator scope requirement for browser control when accessed via the
node.invoke method, despite direct browser.request access requiring such scope. In Gateway deployments that utilize caller identity and narrow operator scopes, a caller with write-scope access to a browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without administrator privileges. The actual impact depends on the browser profile and the current signed-in state. Callers using shared-secret tokens or passwords are not affected as they are treated as fully trusted operators.Recommendations
Update to version 2026.7.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw