Executive brief
OpenClaw is a JavaScript library for gateway operations and message handling. An authenticated user with basic operator privileges can bypass authorization controls to access and modify sensitive admin-only settings, including Telegram bot configuration and system cron jobs, leading to unauthorized system changes and potential persistence mechanisms.
Technical details
The vulnerability is an improper privilege management issue (CWE-269) in the operator.write endpoint. An authenticated attacker with low-level operator privileges can reach admin-class Telegram config and cron persistence mechanisms through the send operation, bypassing intended privilege boundaries. The vulnerability requires valid authentication but does not require additional user interaction. An attacker can use this to modify sensitive system configuration and establish persistence. The issue is fixed in version 2026.3.28 and later.
Affected products
- OpenClaw openclaw <=2026.3.24
Timeline
- 2026-04-07: disclosed
- 2026-03-25: patched: Fix released in version 2026.3.28