Junglewise Threat Intelligence

CVE-2026-43566: OpenClaw privilege escalation via untrusted webhook wake events

CVE-2026-43566 · Severity: low · CVSS 3.1 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript automation and CI/CD orchestration library used in npm-based build pipelines. A flaw in the heartbeat owner-downgrade logic allows untrusted webhook events to execute with elevated privileges (owner context) when they should have been downgraded to lower-privilege execution. An attacker controlling a webhook endpoint could trigger malicious code with unauthorized permissions.

Technical details

The vulnerability is a privilege escalation (CWE-863) and improper access control (CWE-184) in OpenClaw's heartbeat owner-downgrade mechanism. When processing webhook wake events, the library failed to inspect event reasons properly, allowing untrusted webhook events to retain owner-like execution context instead of being downgraded. The fix (PR #66031, commit 31281bc) adds wake and hook event reasons to the owner-downgrade inspection logic and forces downgrade for untrusted hook wake events. Attack vector is network-based (webhook reachable over the network). A remote attacker who can trigger or control webhook events can exploit this by crafting untrusted webhook wake events that bypass the downgrade check. Patch available: upgrade to openclaw 2026.4.14 or later.

Affected products

  • OpenClaw openclaw >= 2026.4.7, < 2026.4.14

Timeline

  • 2026-04-17: disclosed: GHSA advisory published
  • 2026-04-14: patched: Fixed in openclaw 2026.4.14

References

Related threats