Description
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can create or modify browser profiles and persist attacker-controlled remote CDP endpoints to disk without holding operator.admin privileges.
Problem types
Product status
Any version before 2026.3.11
2026.3.11 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-vmhq-cqm9-6p7q (GitHub Security Advisory (GHSA-vmhq-cqm9-6p7q))
www.vulncheck.com/...-profile-management-via-browser-request (VulnCheck Advisory: OpenClaw < 2026.3.11 - Authorization Bypass in Browser Profile Management via browser.request)