Junglewise Threat Intelligence

CVE-2026-45006: OpenClaw improper access control in gateway tool config operations

CVE-2026-45006 · Severity: high · CVSS 8.8 · Published 2026-05-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI agent framework. A security flaw in its gateway tool allows a compromised or malicious AI model to bypass safety restrictions and modify the system's core configuration. This could allow an attacker to gain persistent control over the system, change network behavior, or access sensitive credentials, with changes remaining in effect even after the service is restarted.

Technical details

An improper access control vulnerability (CWE-184/CWE-862) exists in OpenClaw's gateway tool due to an incomplete denylist used to protect sensitive configuration paths. The gateway tool's config.apply and config.patch operations are intended to have a model-to-operator trust boundary; however, because the configuration schema outgrew the manual denylist, sensitive subtrees remained writable. A compromised model or an attacker with low privileges can exploit this over the network to persist malicious modifications to command execution settings, network/proxy behaviors, and operator policies. The vulnerability is fixed in version 2026.4.23 by replacing the denylist with a fail-closed allowlist that only permits a narrow set of agent-tunable paths.

Affected products

  • openclaw openclaw < 2026.4.23

Timeline

  • 2026-04-23: patched: Fix committed to repository.
  • 2026-04-24: advisory: GitHub Security Advisory published.
  • 2026-05-11: disclosed: CVE published to NVD.

References

Related threats