Improper access control in OpenClaw - #VU127180
Published: April 23, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass owner-only access controls.
The vulnerability exists due to improper access control in the MCP loopback path when handling requests with spoofed owner-context metadata in request headers. A remote user can send a specially crafted request with spoofed owner-context metadata to bypass owner-only access controls.