#VU125290 Improper privilege management in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in gateway plugin HTTP routes using auth: gateway when processing identity-bearing operator.read requests from an upstream trusted proxy. A remote user can send a request that declares read scope to obtain runtime operator.write scope and escalate privileges.