PT-2026-37020 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-43535

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.14
Description An authorization context reuse issue exists in collect-mode queue batches. This allows messages from different senders to inherit the authorization context of the final sender. An attacker can exploit this by sending multiple queued messages to drain batches using a more privileged sender's context, resulting in earlier messages executing with elevated permissions.
Recommendations Update to version 2026.4.14 or newer.

Fix

Incorrect Privilege Assignment

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-43535
GHSA-JWRQ-8G5X-5FHM

Affected Products

Openclaw