Improper privilege management in OpenClaw - #VU125290
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in gateway plugin HTTP routes using auth: gateway when processing identity-bearing operator.read requests from an upstream trusted proxy. A remote user can send a request that declares read scope to obtain runtime operator.write scope and escalate privileges.