OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope boundary bypass to gain elevated privileges and perform unauthorized administrative actions.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | npm/openclaw: <= 2026.3.24 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | openclaw | cert_advisory | 90% |
Updated severity to CRITICAL, marked as actively exploited, and noted no exploit available.
Initial creation