Improper privilege management in OpenClaw - #VU125240

 

Improper privilege management in OpenClaw - #VU125240

Published: April 8, 2026


Vulnerability identifier: #VU125240
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform privileged runtime actions.

The vulnerability exists due to improper privilege management in plugin-auth HTTP routes when handling unauthenticated requests before plugin authentication completes. A remote attacker can send a request to plugin-auth routes to perform privileged runtime actions.

The issue is limited to plugin routes that actually touch privileged runtime actions before plugin authentication completes.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.3.31

External References

Related Security Bulletins