Executive brief
OpenClaw is a command framework used to manage application configuration and debugging operations. A flaw in access control allowed users with basic command authorization to access privileged administrative endpoints (/config and /debug) that were intended exclusively for owners, potentially exposing or modifying sensitive configuration and runtime state.
Technical details
OpenClaw documented /config and /debug endpoints as owner-only, but the command handlers performed only a generic "command-authorized" check (isAuthorizedSender) rather than explicitly verifying owner status. An attacker with valid command authorization but non-owner privileges could exploit this authorization bypass to reach protected surfaces. The vulnerability requires command-level authorization to exploit but allows unauthorized reads and modifications of privileged configuration and debugging information. A patch was released in version 2026.3.12 that enforces owner checks at the command handler level and includes regression tests for access control.
Affected products
- OpenClaw OpenClaw <= 2026.3.11
Timeline
- 2026-03-13: disclosed
- 2026-03-12: patched: Fixed in version 2026.3.12