Privilege Escalation Vulnerability in OpenClaw by OpenClaw
CVE-2026-35669

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-35669?

OpenClaw prior to version 2026.3.25 contains a vulnerability that allows attackers to exploit improperly configured gateway-authenticated plugin HTTP routes. This misconfiguration leads to an incorrect issuance of the operator.admin runtime scope, which fails to respect caller-granted scopes. As a result, unauthorized users can leverage this flaw to gain elevated privileges, potentially executing administrative commands without proper authorization. It is crucial for users to update to the latest version to mitigate this risk.

Affected Version(s)

OpenClaw 0 < 2026.3.25

OpenClaw 2026.3.25

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou (@zpbrent)
.