Junglewise Threat Intelligence

CVE-2026-35674: OpenClaw scope bypass in Gateway chat.send route

CVE-2026-35674 · Severity: high · CVSS 8.8 · Published 2026-05-29

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a platform used for managing gateway communications and command execution. A security flaw in its chat routing system allows users with limited permissions to bypass security restrictions and execute high-level administrative commands. This could lead to unauthorized changes to system configurations, security allowlists, and the installation of malicious plugins, potentially compromising the entire platform's integrity and data.

Technical details

A scope bypass vulnerability exists in OpenClaw's Gateway 'chat.send' route due to incorrect authorization (CWE-863) when handling inherited external routes. An attacker with 'operator.write' privileges can deliver commands through these inherited routes, causing the system to evaluate them as external-channel commands while retaining the lower Gateway client scopes. This allows the attacker to bypass 'operator.approvals' and 'operator.admin' scope requirements. Successful exploitation enables unauthorized mutations of plugins, configurations, MCP, allowlists, and ACP. The issue is fixed in version 2026.5.18.

Affected products

  • OpenClaw OpenClaw < 2026.5.18

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory GHSA-hw9r-h9mr-4jff published
  • 2026-05-29: disclosed: NVD publication of CVE-2026-35674
  • 2026-05-18: patched: First stable patched version released

References

Related threats