OpenClaw Authorization Bypass Vulnerability in Browser Profile Management

Vulnerability

An authorization bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.11. This vulnerability allows authenticated operators with only 'operator.write' permission to access admin-only browser profile management routes via 'browser.request'. Exploiting this vulnerability enables attackers to create or modify browser profiles and persist remote Chrome DevTools Protocol (CDP) endpoints to disk, all without requiring 'operator.admin' privileges.

Impact

Exploitation of this vulnerability allows a write-scoped operator to create or modify browser profiles and store attacker-chosen remote CDP endpoints on disk, bypassing the need for admin privileges.

Remediation

Users can upgrade to OpenClaw version 2026.3.11 or later to address this vulnerability. Instructions for updating can be found in the OpenClaw documentation.

Added: Mar 29, 2026, 1:24 PM
Updated: Mar 29, 2026, 1:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
4.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.