PT-2026-31954 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-35619

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to enforce operator read scope requirements. Attackers with only operator.approvals scope can enumerate gateway model metadata through the HTTP compatibility route, bypassing the stricter WebSocket RPC authorization checks.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35619

Affected Products

Openclaw