Scope Bypass Vulnerability in OpenClaw Gateway Chat Feature
CVE-2026-35674
8.7HIGH
What is CVE-2026-35674?
OpenClaw versions prior to 2026.5.18 are susceptible to a scope bypass vulnerability in the Gateway's chat.send route. This issue allows attackers with an operator.write scope to execute privileged commands by circumventing standard scope checks. By leveraging inherited external routes, unauthorized users can bypass operator.approvals and operator.admin scope restrictions, leading to potential modifications of plugins, configurations, multiple control points (MCP), allowlists, and administrative control points (ACP). Immediate action is recommended to secure systems against this vulnerability.
Affected Version(s)
OpenClaw 0 < 2026.5.18
OpenClaw 2026.5.18
