Incorrect authorization in OpenClaw - #VU128586
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify persistent memory dreaming settings.
The vulnerability exists due to incorrect authorization in the /dreaming gateway path when handling operator.write commands. A remote user can send a crafted operator.write command to modify persistent memory dreaming settings.
The issue crosses from a write-scoped gateway capability into an admin-class configuration mutation.