#VU125157 Improper Authorization in OpenClaw - CVE-2026-32914
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to read or modify privileged configuration information.
The vulnerability exists due to improper authorization in /config and /debug command handlers when handling command requests from command-authorized non-owners. A remote user can send command requests to access owner-only configuration and debugging surfaces to read or modify privileged configuration information.
The issue affects lower-trust senders that are permitted to run commands but are not owners.