Incorrect authorization in OpenClaw - #VU132733
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to gain administrative access to gateway RPC functionality.
The vulnerability exists due to incorrect authorization in the Control UI WebSocket handling in trusted-proxy mode when processing a client-declared scope set before pairing is bound to a server-approved authorization baseline. A remote user can open a Control UI WebSocket with a fresh unpaired device identity and request elevated scopes to gain administrative access to gateway RPC functionality.
This issue affects trusted-proxy Control UI deployments and does not apply to shared-secret Control UI sessions.