Missing Authorization in OpenClaw - CVE-2026-35631
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform unauthorized mutating control-plane actions.
The vulnerability exists due to missing authorization in internal ACP chat commands when handling mutating internal ACP actions. A remote user can invoke crafted chat commands to perform unauthorized mutating control-plane actions.
The issue affects mutating commands that should have been restricted by the operator.admin scope separating read-only and mutating actions.