Description
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without device identity verification. Attackers can exploit the device-less allow path in the trusted-proxy mechanism to maintain elevated permissions by declaring arbitrary scopes, bypassing device identity requirements.
Problem types
Execute unauthorized code or commands
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
Nathan (@nexrin)
KeenSecurityLab
References
github.com/...enclaw/security/advisories/GHSA-48vw-m3qc-wr99 (GitHub Security Advisory (GHSA-48vw-m3qc-wr99))
github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1)
github.com/...ommit/ccf16cd8892402022439346ae1d23352e3707e9e (Patch Commit #2)
www.vulncheck.com/...ared-scopes-in-trusted-proxy-control-ui (VulnCheck Advisory: OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI)