Executive brief
OpenClaw is a JavaScript library used for managing operator authentication and authorization in applications. Unauthenticated HTTP routes designated for plugin authentication incorrectly receive elevated operator runtime permissions, allowing unauthorized users to perform privileged operations on systems relying on these routes. This could enable attackers to modify or manipulate application behavior without proper authorization checks.
Technical details
The vulnerability is a privilege management and authorization bypass issue (CWE-269, CWE-862) affecting OpenClaw's plugin-auth HTTP routes. Unauthenticated routes marked with auth:"plugin" incorrectly receive operator WRITE_SCOPE permissions, granting them access to privileged runtime actions before plugin authentication is completed. The vulnerability is network-reachable and requires no authentication or user interaction. An attacker can invoke these routes to execute privileged operations, though the actual impact is limited to plugin routes that handle privileged runtime actions. The vulnerability was patched in version 2026.3.31; versions up to 2026.3.28 are affected.
Affected products
- OpenClaw OpenClaw <=2026.3.28
Timeline
- 2026-03-31: disclosed
- 2026-04-01: patched: Patch commit 2a1db0c0f1fa375004a95ba0ef030534790a6d47