CVE-2026-35645

8.1

OpenClaw · OpenClaw

OpenClaw contains a privilege escalation vulnerability in the gateway plugin subagent deleteSession function that allows authenticated users to execute privileged operations.

Executive summary

A privilege escalation vulnerability in OpenClaw allows authenticated attackers to perform unauthorized administrative actions, posing a significant risk to system integrity.

Vulnerability

The vulnerability resides in the gateway plugin subagent deleteSession function, which incorrectly utilizes a synthetic operator.admin runtime scope. An authenticated attacker can trigger session deletion without a request-scoped client to execute privileged operations with unintended administrative permissions.

Business impact

The ability to perform unauthorized administrative operations via this flaw could lead to full system compromise, loss of data integrity, and unauthorized modification of critical configurations. Given the CVSS score of 8.1, this vulnerability is classified as High severity, as it allows a low-privileged authenticated user to escalate their capabilities to an administrative level.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.3.28 or later to incorporate the vendor-provided fix.

Proactive Monitoring: Review system and application access logs for unusual session management activities or unexpected administrative operations initiated by standard user accounts.

Compensating Controls: Implement strict access control lists and evaluate network-level restrictions to limit the exposure of the gateway plugin subagent to untrusted or unauthorized users.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a clear path for privilege escalation within the OpenClaw platform. Security teams should prioritize patching affected environments to version 2026.3.28 immediately to prevent potential abuse by authenticated actors. Failure to remediate allows for the potential manipulation of system-level functions that could jeopardize the entire application infrastructure.

More OpenClaw CVEs

Sources

Originally found and disclosed by Peng Zhou (@zpbrent), per the CVE Program record.