OpenClaw Authorization Bypass Vulnerability Allowing Unauthorized Session Reset

Vulnerability

A vulnerability in OpenClaw versions prior to 2026.3.11 allows write-scoped callers to bypass authorization and access admin-only session reset functionality. Attackers with operator.write scope can send agent requests with /new or /reset commands to reset conversation states, without needing operator.admin privileges. This vulnerability arises because scope checks were only applied to the outer RPC method, allowing write-scoped callers to access admin-level session mutations.

Impact

Exploitation of this vulnerability allows unauthorized session resets, enabling write-scoped callers to manipulate conversation states by accessing admin-only reset logic.

Remediation

Users are advised to upgrade to OpenClaw version 2026.3.11 or later.

Added: Mar 29, 2026, 1:26 PM
Updated: Mar 29, 2026, 1:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
4.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.