Executive brief
OpenClaw is an AI automation platform that allows different users to have different permission levels. A user with basic "write" permissions (intended for messaging only) could bypass authorization checks and reset conversations that should only be resettable by administrators. This allows an unprivileged user to disrupt or destroy conversation state that they should not have access to modify.
Technical details
The vulnerability is an incorrect authorization check (CWE-863) where scope validation was enforced only at the outer RPC method level but not at internal code paths. The agent slash-command handlers for `/new` and `/reset` internally reused the admin-only session reset logic without re-checking authorization. A caller with operator.write permission could bypass the admin-only operator.admin requirement by issuing agent requests containing /new or /reset slash commands. The fix in version 2026.3.11 refactored reset logic into a shared service with proper scope checks at each entry point, while preserving the admin-only nature of the sessions.reset RPC.
Affected products
- OpenClaw openclaw <= 2026.3.8
Timeline
- 2026-03-13: disclosed: Advisory published
- 2026-03-11: patched: Fix released in version 2026.3.11