PT-2026-31956 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-30

·

Updated

2026-04-10

·

CVE-2026-35621

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.24
Description OpenClaw versions before 2026.3.24 contain a privilege escalation issue. The /allowlist command does not properly re-validate gateway client scopes for internal callers, allowing clients with operator.write scope to modify channel authorization policies. An attacker can leverage chat.send to create an internal command-authorized context and persistently alter channel allowFrom and groupAllowFrom policies, which are normally restricted to operator.admin scope. The vulnerability arises because the /allowlist command persists channel authorization configuration through writeConfigFile() without enforcing the necessary operator.admin scope check for internal gateway callers, unlike /config and /plugins commands. This allows a client authenticated with operator.write to indirectly modify channel authorization state, weakening the control-plane privilege separation.
Recommendations Update to OpenClaw version 2026.3.24 or later to resolve this issue.

Fix

LPE

Missing Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-35621
GHSA-94PW-C6M8-P9P9

Affected Products

Openclaw