Executive brief
OpenClaw is a chat automation framework that processes internal commands to manage allowlists for message routing. An authenticated operator with limited write permissions can bypass authorization checks to modify allowlist configuration and persistent state without requiring full admin rights, even though comparable commands in the same system already enforce this higher permission level.
Technical details
The vulnerability is a missing authorization check (CWE-862) in OpenClaw's internal `/allowlist` chat command handlers. While the command receives basic authorization validation via `rejectUnauthorizedCommand()`, it lacks the required `requireGatewayClientScopeForInternalChannel(..., operator.admin, ...)` check that peer mutating commands (like `/config`, `/mcp`, `/plugins`, `/acp`) already enforce. An authenticated internal Gateway caller with only `operator.write` scope can invoke `/allowlist add` commands to persistently modify both config-backed allowFrom entries and pairing-store-backed allowlist entries. The attack requires network access to the internal Gateway surface and an existing authenticated session with operator.write scope, but no user interaction. The vulnerability was introduced in v2026.1.20 and patched in v2026.3.24.
Affected products
- OpenClaw OpenClaw <= 2026.3.23
Timeline
- 2026-03-30: disclosed: Advisory published
- 2026-03-24: patched: Fixed in version 2026.3.24