OpenClaw Authorization Bypass Vulnerability Allowing Unauthorized Session Reset
Vulnerability
A vulnerability in OpenClaw versions prior to 2026.3.11 allows write-scoped callers to bypass authorization and access admin-only session reset functionality. Attackers with operator.write scope can send agent requests with /new or /reset commands to reset conversation states, without needing operator.admin privileges. This vulnerability arises because scope checks were only applied to the outer RPC method, allowing write-scoped callers to access admin-level session mutations.
Impact
Exploitation of this vulnerability allows unauthorized session resets, enabling write-scoped callers to manipulate conversation states by accessing admin-only reset logic.
Remediation
Users are advised to upgrade to OpenClaw version 2026.3.11 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
