Improper Access Control in OpenClaw Gateway Tool Affects Configuration Management
CVE-2026-45006

7.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-45006?

OpenClaw prior to version 2026.4.23 is susceptible to an improper access control vulnerability within the gateway tool's configuration operations. This flaw allows malicious entities to circumvent insufficient denylist protections, facilitating unauthorized modifications to configurations. Attackers can implement harmful changes that imperil command execution, alter network behaviors, compromise credentials, and manipulate operator policies, with these alterations persisting even after a system restart.

Affected Version(s)

OpenClaw 0 < 2026.4.23

OpenClaw 2026.4.23

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
.