PT-2026-31755 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-34512

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.25
Description OpenClaw contains an improper access control issue in the /sessions/:sessionKey/kill route. Any bearer-authenticated user can invoke admin-level session termination functions without proper scope validation. An attacker can exploit this by sending authenticated requests to terminate arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.
Recommendations Update to version 2026.3.25 or later.

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34512

Affected Products

Openclaw