Incorrect authorization in OpenClaw - #VU126837
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Control UI assistant-media route when handling identity-bearing HTTP authentication paths for trusted-proxy callers. A remote user can send a request through a trusted proxy without the required operator.read scope to disclose sensitive information.
The route still requires successful gateway authentication and media-root checks.