CVE-2026-35631
OpenClaw < 2026.3.22 - Missing Authorization Enforcement in Internal ACP Chat Commands
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
09 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unauthorized modifications. Attackers without admin privileges can execute mutating control-plane actions by directly invoking affected ACP commands to bypass authorization gates.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
OpenClaw · OpenClawWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/openclaw/openclaw/commit/229426a257e49694a59fa4e3895861d02a4d767fhttps://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87https://github.com/openclaw/openclaw/security/advisories/GHSA-3w6x-gv34-mqpfhttps://www.vulncheck.com/advisories/openclaw-missing-authorization-enforcement-in-internal-acp-chat-commands