OpenClaw Privilege Escalation Vulnerability Allowing Remote Code Execution

Vulnerability

A privilege escalation vulnerability has been identified in OpenClaw versions prior to 2026.3.31. This vulnerability allows paired nodes with the role of 'node' to send 'node.event' agent requests that bypass restrictions on gateway-side tool access. As a result, attackers with trusted paired node credentials can exploit this vulnerability to escalate privileges and execute remote code on the gateway.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, leading to remote code execution on the gateway.

Reproduction

The vulnerability can be reproduced by a paired node with the 'node' role. The node can dispatch 'node.event' agent requests to the gateway, using trusted credentials to gain unauthorized access to gateway-side tools. This unrestricted access can then be leveraged to execute code remotely on the gateway.

Remediation

Users can upgrade to OpenClaw version 2026.3.31 or later to address this vulnerability.

Added: Apr 28, 2026, 9:46 PM
Updated: Apr 28, 2026, 9:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.3
remediation
0.0
relevance
6.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.