Incorrect Privilege Assignment in OpenClaw - #VU125199

 

Incorrect Privilege Assignment in OpenClaw - #VU125199

Published: April 8, 2026


Vulnerability identifier: #VU125199
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete sessions beyond their intended authorization scope.

The vulnerability exists due to incorrect privilege assignment in the gateway plugin subagent fallback deleteSession path when no request-scoped client exists. A remote user can trigger session deletion through the fallback path to delete sessions beyond their intended authorization scope.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.


External References

Related Security Bulletins