Scope Bypass Vulnerability in OpenClaw Gateway Chat Feature
CVE-2026-35674

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-35674?

OpenClaw versions prior to 2026.5.18 are susceptible to a scope bypass vulnerability in the Gateway's chat.send route. This issue allows attackers with an operator.write scope to execute privileged commands by circumventing standard scope checks. By leveraging inherited external routes, unauthorized users can bypass operator.approvals and operator.admin scope restrictions, leading to potential modifications of plugins, configurations, multiple control points (MCP), allowlists, and administrative control points (ACP). Immediate action is recommended to secure systems against this vulnerability.

Affected Version(s)

OpenClaw 0 < 2026.5.18

OpenClaw 2026.5.18

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dikai Zou
.