CVE-2026-32051 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-…
High CVSS: 8.7

CVE-2026-32051

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-863
Yayın Tarihi
2026-03-21 01:17:08
Güncelleme
2026-03-23 17:08:11
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar