PT-2026-31755 · Openclaw · Openclaw

·

CVE-2026-34512

·

Published

2026-03-27

·

Updated

2026-04-10

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.25
Description OpenClaw contains an improper access control issue in the /sessions/:sessionKey/kill route. Any bearer-authenticated user can invoke admin-level session termination functions without proper scope validation. An attacker can exploit this by sending authenticated requests to terminate arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.
Recommendations Update to version 2026.3.25 or later.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34512
GHSA-9P93-7J67-5PC2

Affected Products

Openclaw