CVE-2026-35638

8.8

OpenClaw · OpenClaw

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes.

Executive summary

A privilege escalation vulnerability in the OpenClaw Control UI allows unauthorized actors to obtain elevated permissions, posing a significant risk of total system compromise.

Vulnerability

The flaw resides in the trusted-proxy mechanism of the Control UI, where the system fails to verify device identity. By exploiting the device-less allow path, an attacker can declare arbitrary scopes to gain elevated privileges without authentication.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to full system compromise. If exploited, an attacker could gain unauthorized administrative access, leading to potential data breaches, unauthorized execution of commands, and total loss of confidentiality, integrity, and availability of the affected system.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.3.22 or later immediately to apply the necessary patch for the trusted-proxy mechanism.

Proactive Monitoring: Review access logs for anomalous session activity and unexpected privilege escalations or unauthorized configuration changes within the Control UI.

Compensating Controls: Implement strict network segmentation and restrict access to the Control UI via a Web Application Firewall (WAF) to block requests attempting to inject arbitrary scopes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, organizations should prioritize patching OpenClaw immediately. Failure to update allows for potential remote exploitation that could result in total system control. Ensure that all instances are updated to version 2026.3.22 to effectively remediate this security risk.

More OpenClaw CVEs

Sources

Originally found and disclosed by Nathan (@nexrin), KeenSecurityLab, per the CVE Program record.