OpenClaw Improper Access Control Vulnerability in Gateway Tool Allowing Unsafe Config Mutations

Vulnerability

A vulnerability in OpenClaw versions prior to 2026.4.23 allows compromised models to bypass access controls in the gateway tool's config.apply and config.patch operations. This flaw arises from an incomplete denylist protection, enabling the models to write unsafe configuration changes. The malicious modifications can affect command execution, network behavior, credentials, and operator policies, persisting through restarts.

Impact

Exploitation of this vulnerability could lead to unauthorized configuration changes that bypass security controls, allowing a model to manipulate sensitive aspects of the application such as command execution rights, network and proxy settings, credential management, and operator policies. These changes could persist after a restart, potentially leading to long-term security issues.

Reproduction

To reproduce this vulnerability, a model must be prompted to make configuration changes through the gateway tool's 'config.apply' or 'config.patch' actions. The model can be injected with a prompt that exploits the access control bypass, allowing it to write unsafe configurations. This can be done by manipulating the model's input to include harmful directives that alter protected config paths, such as those related to command execution or network behavior.

Remediation

Users can update to OpenClaw version 2026.4.23 or later, where this vulnerability has been addressed by replacing the denylist with a fail-closed allowlist for gateway config mutations.

Added: May 11, 2026, 6:59 PM
Updated: May 11, 2026, 6:59 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.8
remediation
0.0
relevance
8.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.