Description
OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking affected ACP commands to bypass authorization gates.
Problem types
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-3w6x-gv34-mqpf (GitHub Security Advisory (GHSA-3w6x-gv34-mqpf))
github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1)
github.com/...ommit/229426a257e49694a59fa4e3895861d02a4d767f (Patch Commit #2)
www.vulncheck.com/...forcement-in-internal-acp-chat-commands (VulnCheck Advisory: OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands)