PT-2026-26620 · Openclaw · Openclaw

Yekai Chen

·

Published

2026-03-13

·

Updated

2026-04-02

·

CVE-2026-22172

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.12
Description OpenClaw contains an authorization bypass issue in the WebSocket connect path. This flaw allows shared-token or password-authenticated connections to self-declare elevated scopes, such as operator.admin, without server-side verification. An attacker can exploit this to perform administrative operations. The issue stems from a logic flaw where client-declared scopes were not properly bound on the server-side for certain connection types. This allowed a shared-authenticated client to present elevated scopes even without a device identity or trusted Control UI path.
Recommendations Versions prior to 2026.3.12 should be updated to version 2026.3.12 or later.

Fix

Missing Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-22172
GHSA-RQPP-RJJ8-7WV8
GHSA-X49Q-FHHM-R9JF

Affected Products

Openclaw