#VU125105 Incorrect authorization in OpenClaw - CVE-2026-32051
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to perform control-plane actions beyond intended write scope.
The vulnerability exists due to incorrect authorization in owner-only tool surfaces accessed through agent runs when processing authenticated agent execution requests in scoped-token deployments. A remote user can invoke owner-only tool surfaces through agent runs to perform control-plane actions beyond intended write scope.
Only scoped-token deployments are vulnerable.