Privilege Escalation in OpenClaw Gateway Plugin by OpenClaw
CVE-2026-35645

6.1MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-35645?

OpenClaw versions before 2026.3.25 are susceptible to a privilege escalation vulnerability found in the gateway plugin's deleteSession function. This issue allows attackers to manipulate session deletions without a request-scoped client, which can lead to executing privileged operations unintentionally. The exploitation of this vulnerability could give attackers unauthorized access to critical administrative functions, potentially compromising system integrity.

Affected Version(s)

OpenClaw 0 < 2026.3.25

OpenClaw 2026.3.25

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou (@zpbrent)
.