Insufficient Access Control in OpenClaw Nostr Plugin
CVE-2026-43579

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-43579?

OpenClaw versions prior to 2026.4.10 are susceptible to an insufficient access control vulnerability in the Nostr plugin's HTTP profile routes. This flaw enables operators with write permissions to persist changes to profile configurations without needing admin privileges. Attackers with the operator.write scope can leverage this oversight to modify Nostr profile settings through unprotected mutation endpoints. This unauthorized modification could lead to persistent changes, compromising the integrity of user configurations.

Affected Version(s)

OpenClaw 0 < 2026.4.10

OpenClaw 2026.4.10

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peng Zhou (@zpbrent)
.