Incorrect authorization in OpenClaw - CVE-2026-41404
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect authorization in trusted-proxy authentication mode when processing identity-bearing authentication paths for non-Control-UI clients. A remote user can self-declare operator scopes to escalate privileges.
Only non-Control-UI clients using trusted-proxy authentication mode are affected.