Privilege Escalation Vulnerability in OpenClaw by OpenClaw
CVE-2026-43568
7.1HIGH
What is CVE-2026-43568?
OpenClaw versions 2026.4.5 through 2026.4.10 exhibit a privilege escalation vulnerability that allows attackers with write-scoped gateway access to manipulate the '/dreaming' endpoint. This flaw enables them to toggle admin-class configuration parameters, posing significant security risks by compromising the integrity of persistent memory dreaming settings. An urgent patch has been released to mitigate this vulnerability.
Affected Version(s)
OpenClaw 2026.4.5 < 2026.4.10
OpenClaw 2026.4.10
