Improper Access Control in OpenClaw Gateway Tool Affects Configuration Management
CVE-2026-45006
7.7HIGH
What is CVE-2026-45006?
OpenClaw prior to version 2026.4.23 is susceptible to an improper access control vulnerability within the gateway tool's configuration operations. This flaw allows malicious entities to circumvent insufficient denylist protections, facilitating unauthorized modifications to configurations. Attackers can implement harmful changes that imperil command execution, alter network behaviors, compromise credentials, and manipulate operator policies, with these alterations persisting even after a system restart.
Affected Version(s)
OpenClaw 0 < 2026.4.23
OpenClaw 2026.4.23
