CVE-2026-22172
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.
Vendor
Product
CWE
Yayın Tarihi
2026-03-20 15:16:15
Güncelleme
2026-03-24 21:20:45
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-