OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow path in the trusted-proxy mechanism to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.
References
Configurations
History
No history.
Information
Published : 2026-04-09 22:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35638
Mitre link : CVE-2026-35638
CVE.ORG link : CVE-2026-35638
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-286
Incorrect User Management
