OpenClaw Missing Authorization Enforcement on ACP Commands Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.3.22, where the operator.admin scope is not properly enforced on mutating internal ACP chat commands. This oversight allows unauthorized users to make changes by directly invoking these ACP commands, bypassing the necessary authorization checks. As a result, attackers without admin privileges can execute mutating control-plane actions.

Impact

Exploitation of this vulnerability allows unauthorized users to perform mutating actions on the control plane via internal ACP commands, potentially leading to unauthorized modifications within the application.

Reproduction

To reproduce this vulnerability, use an OpenClaw version prior to 2026.3.22. Without admin privileges, invoke mutating ACP commands that are not gated by the operator.admin scope. This can be done through the ACP command interface, where the lack of proper authorization enforcement will allow the actions to be executed successfully.

Remediation

Users can upgrade to OpenClaw version 2026.3.22 or later, where this vulnerability has been addressed.

Added: Apr 9, 2026, 11:52 PM
Updated: Apr 9, 2026, 11:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
5.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.