Junglewise Threat Intelligence

OpenClaw privilege escalation in internal/webchat command authentication

Severity: low · CVSS 3.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular automation and workflow orchestration platform. A privilege escalation vulnerability in its internal and webchat command authentication allows attackers with lower privileges to execute commands with owner-level permissions outside their intended scope, potentially bypassing access controls and channel boundaries.

Technical details

This is a privilege escalation vulnerability (CWE-863: Improper Authorization) affecting OpenClaw's internal and webchat command authentication. The root cause is improper state handling where the wildcard ownerAllowFrom configuration can be inherited across channel boundaries when processing commands. An authenticated attacker sending commands on internal or webchat paths can inherit elevated permissions meant for a different channel context, allowing execution of owner-style behavior without proper authorization checks. The vulnerability requires authentication and network access. The first patched version is 2026.4.25; versions 2026.4.24 and earlier are affected.

Affected products

  • OpenClaw OpenClaw before 2026.4.25

Timeline

  • 2026-05-28: disclosed: Advisory published by OpenClaw on GitHub
  • 2026-04-25: patched: First stable patched version released

References

Related threats