Improper privilege management in OpenClaw - #VU126438
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to retain execution in a more privileged context than intended.
The vulnerability exists due to improper privilege management in heartbeat owner-downgrade detection when processing local background exec completion events. A local user can supply untrusted completion content to retain execution in a more privileged context than intended.
The issue occurs because local async exec completion text could be missed by the detection logic.