PT-2026-29226 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-13

·

Updated

2026-04-09

·

CVE-2026-32916

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.3.7 through 2026.3.10
Description The software contains an authorization bypass issue where plugin subagent routes execute gateway methods using a synthetic operator client with extensive administrative permissions. Unauthenticated remote requests to routes owned by plugins can trigger runtime.subagent methods, enabling privileged gateway actions such as session deletion and agent execution.
Recommendations Update to version 2026.3.11 or later.

Fix

Improper Authorization

Incorrect Privilege Assignment

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-32916
GHSA-PHGF-3849-RGJQ
GHSA-XW77-45GV-P728

Affected Products

Openclaw