PT-2026-35807 · Openclaw · Openclaw
Keensecuritylab
+1
·
Published
2026-04-28
·
Updated
2026-04-28
·
CVE-2026-42429
CVSS v3.1
7.1
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator.read requests into runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations.
Fix
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw