Junglewise Threat Intelligence

OpenClaw Gateway tool escalation and ACP permission auto-approval

Severity: low · CVSS 3.1 · Published 2026-03-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw Gateway is an HTTP service that allows authenticated users to invoke tools for automation and orchestration tasks. Two security flaws allowed attackers with valid credentials to escalate privileges: they could invoke dangerous session-control tools (like spawning agent sessions) that should have been restricted, and the permission approval system would automatically grant access to risky operations without proper user confirmation. Combined, these issues could enable attackers with a valid token to gain remote command execution capabilities.

Technical details

The vulnerability comprises two related issues in OpenClaw Gateway. First, the POST /tools/invoke HTTP endpoint did not deny high-risk session orchestration tools (sessions_spawn, sessions_send) by default, allowing authenticated callers to escalate from simple tool invocation to spawning or controlling agent sessions. Second, the ACP (access control permission) system would auto-approve permission requests for dangerous operations (exec, fs_write, etc.) without interactive user confirmation, reducing friction that should prevent silent execution. An authenticated attacker with network access to the Gateway can invoke these dangerous tools to achieve command execution depending on tool policy and runtime environment. The fix hardens default behavior by implementing a deny list for high-risk HTTP tools (PR #15390), requiring interactive confirmation for all non-read/search permissions, and improving permission classification to avoid accidental approvals.

Affected products

  • OpenClaw OpenClaw < 2026.2.14

Timeline

  • 2026-02-14: disclosed
  • 2026-02-13: patched: Fixed in version 2026.2.14

References

Related threats