Junglewise Threat Intelligence

CVE-2026-32976: OpenClaw authorization bypass in channel commands

CVE-2026-32976 · Severity: medium · CVSS 6.5 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and channel management platform, contains a security flaw that allows a user on one account to modify the settings of other accounts on the same system. Even if an account is specifically configured to prevent settings changes, an attacker with basic access can use certain commands to bypass these protections. This could lead to unauthorized configuration changes, potentially disrupting services or altering security policies for other customers or departments sharing the same installation.

Technical details

An authorization bypass vulnerability (CWE-639) exists in OpenClaw versions prior to 2026.3.11. The vulnerability stems from the mutation path validating the origin account's scope but failing to consistently re-authorize the resolved target scope during channel-initiated configuration changes. A remote attacker with low privileges (authorized access to at least one account) can use channel commands such as '/config set' or '/allowlist' to modify the configuration of sibling accounts, even those where 'configWrites' is set to false. This allows for unauthorized modification of protected account-scoped configurations within a single gateway deployment. The issue is resolved in version 2026.3.11 by enforcing authorization checks against both the origin and every resolved target scope.

Affected products

  • OpenClaw OpenClaw < 2026.3.11

Timeline

  • 2026-03-12: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: NVD and VulnCheck publication
  • 2026-03-11: patched: Fix released in version 2026.3.11

References

Related threats