โ† Back to all CVEs

CVE-2026-22172

CRITICAL openclaw NVD
CVSS Score 9.9
Severity CRITICAL
Published Mar 20, 2026
Vendor openclaw

Description

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.

References