CVE-2026-22172
CRITICAL
openclaw
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Mar 20, 2026
Vendor
openclaw
Description
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.