#VU126428 Improper access control in OpenClaw
Published: April 17, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in config.get redaction handling when returning configuration data through sourceConfig and runtimeConfig aliases. A remote user can read configuration data through alias fields that survive redaction to disclose sensitive information.
The issue affects authenticated gateway clients with config read access.