#VU125199 Incorrect Privilege Assignment in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to delete sessions beyond their intended authorization scope.
The vulnerability exists due to incorrect privilege assignment in the gateway plugin subagent fallback deleteSession path when no request-scoped client exists. A remote user can trigger session deletion through the fallback path to delete sessions beyond their intended authorization scope.