PT-2026-28446 · Openclaw · Openclaw
Tdjackey
·
Publicado
2026-03-29
·
Atualizado
2026-03-29
·
CVE-2026-32914
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.12
Description
OpenClaw before version 2026.3.12 has an insufficient access control issue in the
/config and /debug command handlers. Command-authorized non-owners can access owner-only surfaces, allowing them to read or modify privileged configuration settings. The issue stems from missing owner-level permission checks within these handlers. Exploitation requires existing command authorization, and does not require a specific network position. The /config and /debug API endpoints are affected. The vulnerable parameters are not specified.Recommendations
Update OpenClaw to version 2026.3.12 or later.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openclaw