Description
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.
Problem types
CWE-863: Incorrect Authorization
Product status
Any version before 2026.3.1
2026.3.1 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-jr6x-2q95-fh2g (GitHub Security Advisory (GHSA-jr6x-2q95-fh2g))
www.vulncheck.com/...n-agent-runs-via-owner-only-tool-access (VulnCheck Advisory: OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access)