OpenClaw Privilege Escalation Vulnerability in Gateway Plugin HTTP Authentication

Vulnerability

A privilege escalation vulnerability has been identified in OpenClaw versions prior to 2026.4.8. The issue resides in the gateway plugin's HTTP authentication mechanism, where identity-bearing 'operator.read' requests are improperly elevated to 'operator.write' permissions. This vulnerability allows unauthorized write access to runtime operations by sending read-scoped requests through the gateway authentication route.

Impact

Exploitation of this vulnerability allows for unauthorized write access to runtime operations, bypassing intended read-only permissions.

Reproduction

The vulnerability can be reproduced by sending HTTP requests that include the 'operator.read' identity scope through the gateway authentication route. The gateway plugin will incorrectly grant 'operator.write' permissions, allowing unauthorized modifications to runtime operations.

Remediation

Users can upgrade to OpenClaw version 2026.4.8 or later to address this vulnerability.

Added: Apr 28, 2026, 8:20 PM
Updated: Apr 28, 2026, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
6.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.