Junglewise Threat Intelligence

CVE-2026-35638: OpenClaw Trusted-proxy Control UI privilege escalation without device identity

CVE-2026-35638 · Severity: info · Published 2026-03-26

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform that includes a Control UI for managing gateway connections. The vulnerability allows sessions connected through a trusted proxy without device identity verification to retain privileged scopes (admin or secrets access) that should only be granted to properly-authenticated devices. An attacker with network access to the trusted proxy could bypass device identity checks and gain unauthorized administrative or secrets access.

Technical details

The vulnerability is an authorization/privilege escalation flaw in the gateway WebSocket connection handling. Sessions originating from a trusted proxy without device identity could retain self-declared privileged scopes (admin or secrets) on the device-less allow path (handled in src/gateway/server/ws-connection/connect-policy.ts). The root cause is that scope validation was not properly stripping unbound self-declared scopes for device-less connections. An unauthenticated or minimally-authenticated attacker with network access to the trusted proxy can exploit this by crafting a WebSocket connection and self-declaring privileged scopes without presenting a valid device identity. The fix (commit ccf16cd) adds scope scrubbing in src/gateway/server/ws-connection/message-handler.ts to strip unbound self-declared scopes on the no-device path, preventing privilege retention without device identity. The patch shipped in version 2026.3.22 and later.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-26: disclosed: Advisory GHSA-48vw-m3qc-wr99 published
  • 2026-03-17: patched: Fix committed (ccf16cd); released in v2026.3.22

References