#VU125203 Improper privilege management in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in the gateway backend reconnect logic when processing backend-labeled reconnects that request broader scopes. A remote user can reconnect with self-requested elevated scopes to escalate privileges.
The issue allows a non-admin operator scope to self-claim operator.admin by bypassing pairing during reconnect.