Junglewise Threat Intelligence

CVE-2026-35663: OpenClaw privilege escalation in gateway backend reconnect

CVE-2026-35663 · Severity: critical · CVSS 8.8 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a gateway backend service. A vulnerability in its reconnection logic allows users with limited permissions to upgrade their own access to full administrator status. This could lead to unauthorized access to sensitive data and full control over the system's operations.

Technical details

A privilege escalation vulnerability exists in OpenClaw due to improper authorization checks during backend-labeled reconnection. The system previously allowed reconnecting sessions to self-request broader scopes and bypass the pairing process if they were labeled as backend components. An attacker with low-privileged 'operator' access can exploit this by requesting the 'operator.admin' scope during a reconnect, effectively bypassing security baselines. The fix, implemented in commit d3d8e316bd819d3c7e34253aeb7eccb2510f5f48, removes the self-pairing skip and enforces pairing whenever requested scopes exceed the approved baseline.

Affected products

  • OpenClaw openclaw <= 2026.3.24

Timeline

  • 2026-03-26: disclosed
  • 2026-03-27: advisory: GHSA-9hjh-fr4f-gxc4 published

References

Related threats