Junglewise Threat Intelligence

CVE-2026-32914: OpenClaw privilege escalation via improper authorization in /config and /debug

CVE-2026-32914 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a command framework used to manage application configuration and debugging operations. A flaw in access control allowed users with basic command authorization to access privileged administrative endpoints (/config and /debug) that were intended exclusively for owners, potentially exposing or modifying sensitive configuration and runtime state.

Technical details

OpenClaw documented /config and /debug endpoints as owner-only, but the command handlers performed only a generic "command-authorized" check (isAuthorizedSender) rather than explicitly verifying owner status. An attacker with valid command authorization but non-owner privileges could exploit this authorization bypass to reach protected surfaces. The vulnerability requires command-level authorization to exploit but allows unauthorized reads and modifications of privileged configuration and debugging information. A patch was released in version 2026.3.12 that enforces owner checks at the command handler level and includes regression tests for access control.

Affected products

  • OpenClaw OpenClaw <= 2026.3.11

Timeline

  • 2026-03-13: disclosed
  • 2026-03-12: patched: Fixed in version 2026.3.12

References

Related threats