PT-2026-23548 · Openclaw · Openclaw

Yueyuel

·

Published

2026-02-17

·

Updated

2026-03-31

·

CVE-2026-28473

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.2
Description The software contains an authorization bypass issue where clients with operator.write scope can approve or deny exec approval requests by sending the /approve chat command. The /approve command path invokes exec.approval.resolve through an internal privileged gateway client, bypassing the operator.approvals permission check that protects direct RPC calls. This is particularly relevant in shared or multi-client setups where tokens are intentionally scoped differently. The vulnerable function is exec.approval.resolve. The API endpoint used is /approve.
Recommendations Upgrade to OpenClaw version 2026.2.2 or later. If an upgrade is not possible, avoid issuing write-only device tokens to untrusted clients. If an upgrade is not possible, disable text commands (commands.text=false). If an upgrade is not possible, restrict access to the webchat or control UI.

Fix

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-28473
GHSA-MQPW-46FH-299H

Affected Products

Openclaw