PT-2026-31956 · Openclaw · Openclaw

·

CVE-2026-35621

·

Published

2026-03-30

·

Updated

2026-04-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.24
Description OpenClaw versions before 2026.3.24 contain a privilege escalation issue. The /allowlist command does not properly re-validate gateway client scopes for internal callers, allowing clients with operator.write scope to modify channel authorization policies. An attacker can leverage chat.send to create an internal command-authorized context and persistently alter channel allowFrom and groupAllowFrom policies, which are normally restricted to operator.admin scope. The vulnerability arises because the /allowlist command persists channel authorization configuration through writeConfigFile() without enforcing the necessary operator.admin scope check for internal gateway callers, unlike /config and /plugins commands. This allows a client authenticated with operator.write to indirectly modify channel authorization state, weakening the control-plane privilege separation.
Recommendations Update to OpenClaw version 2026.3.24 or later to resolve this issue.

Exploit

Fix

LPE

Improper Privilege Management

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35621
GHSA-94PW-C6M8-P9P9

Affected Products

Openclaw