Improper access control in OpenClaw - #VU126832
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify protected operator settings.
The vulnerability exists due to improper access control in the gateway config.patch and config.apply guard when processing model-driven gateway configuration mutations. A remote user can use the owner-only gateway tool through a prompt-injected model to modify protected operator settings.
This is a model-to-operator guard bypass rather than a remote unauthenticated gateway compromise.