CVE-2026-35669

8.8

OpenClaw · OpenClaw

OpenClaw versions prior to 2026.3.25 contain a privilege escalation vulnerability in gateway authenticated plugin routes that allows authenticated users to incorrectly gain operator.admin scopes.

Executive summary

An authenticated privilege escalation vulnerability in OpenClaw allows low privileged users to gain administrative control over the platform, posing a significant risk to system integrity.

Vulnerability

This vulnerability involves the incorrect use of privileged APIs within gateway authenticated plugin HTTP routes. An authenticated attacker can exploit this scope boundary bypass to mint operator.admin runtime scopes, granting them unauthorized administrative privileges.

Business impact

The ability for an authenticated user to escalate privileges to administrative levels represents a critical business risk, potentially leading to unauthorized data modification, system configuration changes, or full administrative compromise. With a CVSS score of 8.8, this high severity flaw warrants immediate attention to prevent malicious actors from abusing legitimate credentials to bypass intended security controls and exert control over the application environment.

Remediation

Immediate Action: Update OpenClaw to version 2026.3.25 or later to resolve the incorrect scope minting logic.

Proactive Monitoring: Review system access logs for anomalous administrative actions or unexpected privilege usage associated with standard user accounts.

Compensating Controls: Implement strict Web Application Firewall rules to monitor and block suspicious HTTP requests targeting plugin routes if an immediate update is not feasible.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the severity of this privilege escalation flaw, organizations should prioritize patching their OpenClaw instances immediately. Failure to update allows any authenticated user to potentially become an administrator, which could lead to a total compromise of the application environment. Please verify that all plugin routes are protected by upgrading to the fixed version 2026.3.25 as soon as possible.

More OpenClaw CVEs

Sources

Originally found and disclosed by Peng Zhou (@zpbrent), per the CVE Program record.