CVE-2026-32051

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:35

Type Values Removed Values Added
Summary
  • (es) Versiones de OpenClaw anteriores a 2026.3.1 contienen una vulnerabilidad de desajuste de autorización que permite a los llamadores autenticados con alcance operator.write invocar superficies de herramientas solo para propietarios, incluyendo gateway y cron, a través de ejecuciones de agente en despliegues de tokens con alcance. Atacantes con acceso de alcance de escritura pueden realizar acciones del plano de control más allá de su nivel de autorización previsto al explotar una restricción inconsistente solo para propietarios durante la ejecución del agente.

23 Mar 2026, 17:08

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-jr6x-2q95-fh2g - () https://github.com/openclaw/openclaw/security/advisories/GHSA-jr6x-2q95-fh2g - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-agent-runs-via-owner-only-tool-access - () https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-agent-runs-via-owner-only-tool-access - Third Party Advisory

21 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 01:17

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32051

Mitre link : CVE-2026-32051

CVE.ORG link : CVE-2026-32051


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-863

Incorrect Authorization