Skip to main content
Mallory
Back to intelligence
identity-authentication-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerability

OpenClaw Flaws Let Authenticated Users Escalate Privileges and Bypass Authorization

Updated 1mo agoFirst seen Mar 21, 20265 sources

Two high-severity vulnerabilities in OpenClaw exposed paths for authenticated users to gain access beyond their intended roles. CVE-2026-32042 affects versions before 2026.2.25 and allows an attacker with valid shared gateway authentication to present a self-signed, unpaired device identity and bypass pairing requirements, then self-assign elevated operator scopes including operator.admin. The issue is classified as CWE-863 and effectively turns a trusted but unapproved device identity into a route for privilege escalation.

A second flaw, CVE-2026-32051, affects OpenClaw versions before 2026.3.1 and allows users with operator.write scope to reach owner-only tool surfaces such as gateway and cron through agent runs in scoped-token deployments. The authorization mismatch lets lower-privileged authenticated users perform control-plane actions that should be restricted to owners, creating high risk to confidentiality, integrity, and availability. Advisories for both issues point to fixes and security guidance through GitHub and VulnCheck.

Share:
OpenClaw Flaws Let Authenticated Users Escalate Privileges and Bypass Authorization
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 29, 20262mo ago

OpenClaw discloses HTTP session history authorization bypass

A newly reported OpenClaw Gateway flaw allowed authenticated users without the required operator.read scope to access chat session history through the HTTP endpoint /sessions/:sessionKey/history. The issue was caused by inconsistent authorization checks between the WebSocket path, which enforced scope validation, and the HTTP transport layer, which only verified token validity and user identity.

GHSA-5JVJ-HXMH-6H6J: GHSA-5JVJ-HXMH-6H6J: Authorization Bypass in OpenClaw Gateway HTTP Session History | CVEReports
Mar 26, 20262mo ago

OpenClaw fixes trusted-proxy session scope flaw

OpenClaw patched a vulnerability in its gateway WebSocket message handler that let attacker-injected scopes persist in sessions when authorization was granted through a trusted proxy and isControlUi was set to true. The fix in commit ccf16cd8892402022439346ae1d23352e3707e9e added trustedProxyAuthOk to ensure unbound scopes are always scrubbed for proxied sessions.

GHSA-48VW-M3QC-WR99: GHSA-48VW-M3QC-WR99: Improper Privilege Management in OpenClaw Gateway Trusted-Proxy Sessions | CVEReports
Mar 21, 20262mo ago

CVE-2026-32051 is publicly disclosed

CVE-2026-32051 was publicly disclosed as a high-severity OpenClaw authorization bypass vulnerability, with CWE-863 classification, CVSS details, and references to GitHub and VulnCheck advisories. The disclosure described how operator.write users could access owner-only control-plane functionality through agent runs.

CVE-2026-32042 is publicly disclosed

The privilege escalation vulnerability CVE-2026-32042 was disclosed with CWE-863 classification, CVSS scoring, and references to a GitHub security advisory and a VulnCheck advisory. The record states it was newly received by disclosure@vulncheck.com on March 21, 2026.

Mar 1, 20263mo ago

OpenClaw fixes authorization bypass flaw in version 2026.3.1

OpenClaw released version 2026.3.1 to remediate CVE-2026-32051, an authorization bypass affecting earlier versions that allowed authenticated users with operator.write scope to reach owner-only tool surfaces such as gateway and cron through agent runs. The issue stemmed from inconsistent owner-only access checks during agent execution in scoped-token deployments.

Feb 25, 20263mo ago

OpenClaw fixes privilege escalation flaw in version 2026.2.25

OpenClaw addressed CVE-2026-32042, a privilege escalation issue affecting versions 2026.2.22 before 2026.2.25 that let authenticated users with shared gateway access use an unpaired self-signed device identity to obtain elevated operator scopes, including operator.admin. The CVE record references a fixing commit and related advisories for the issue.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.