PT-2026-31773 · Openclaw · Openclaw
Keensecuritylab
+1
·
Published
2026-04-09
·
Updated
2026-04-12
·
CVE-2026-35638
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.22
Description
OpenClaw contains a privilege escalation issue in the Control UI. Unauthenticated sessions can retain self-declared privileged scopes without device identity verification. Attackers can exploit the trusted-proxy mechanism's device-less allow path to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.
Recommendations
Update to version 2026.3.22 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw