PT-2026-28453 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-29
·
Updated
2026-03-30
·
CVE-2026-32972
CVSS v3.1
7.1
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.11
Description
An authorization bypass exists that allows authenticated operators with
operator.write permission to access admin-only browser profile management routes via browser.request. This allows attackers to create or modify browser profiles and persist attacker-controlled remote CDP endpoints to disk without operator.admin privileges. The affected API endpoint is browser.request.Recommendations
Update to version 2026.3.11 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw