OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope requirements, enabling unauthorized plugin, config, MCP, allowlist, and ACP mutations.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-hw9r-h9mr-4jff | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-scope-bypass-via-inherited-chat-send-route | Third Party Advisory |
Configurations
History
01 Jun 2026, 18:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-hw9r-h9mr-4jff - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-scope-bypass-via-inherited-chat-send-route - Third Party Advisory | |
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:-:*:*:*:node.js:*:* |
29 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-29 16:16
Updated : 2026-06-01 18:22
NVD link : CVE-2026-35674
Mitre link : CVE-2026-35674
CVE.ORG link : CVE-2026-35674
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
