PT-2026-29226 · Openclaw · Openclaw
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.3.7 through 2026.3.10
Description
An authorization bypass exists in the plugin subagent runtime where gateway methods are executed through a synthetic operator client with broad administrative scopes. This occurs because plugin-owned HTTP routes using
auth: "plugin" bypass normal gateway authorization and fail to preserve the original caller's authentication context or least-privilege scope. Consequently, remote unauthenticated requests to these routes can invoke runtime.subagent methods to perform privileged actions, such as deleting sessions, reading session data, and triggering agent execution. Approximately 180,000 systems are potentially affected.Recommendations
Update OpenClaw to version 2026.3.11.
Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw