PT-2026-26620 · Openclaw · Openclaw

Yekai Chen

·

Publicado

2026-03-13

·

Atualizado

2026-04-02

·

CVE-2026-22172

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.12
Description OpenClaw contains an authorization bypass issue in the WebSocket connect path. This flaw allows shared-token or password-authenticated connections to self-declare elevated scopes, such as operator.admin, without server-side verification. An attacker can exploit this to perform administrative operations. The issue stems from a logic flaw where client-declared scopes were not properly bound on the server-side for certain connection types. This allowed a shared-authenticated client to present elevated scopes even without a device identity or trusted Control UI path.
Recommendations Versions prior to 2026.3.12 should be updated to version 2026.3.12 or later.

Correção

Missing Authorization

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22172
GHSA-RQPP-RJJ8-7WV8
GHSA-X49Q-FHHM-R9JF

Produtos afetados

Openclaw