


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 21:20:20
Source:
nvd.nist.gov
Identity & Access, Web Technologies
OpenClaw versions before 2026.4.8 contain a critical privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism. The flaw allows attackers to escalate operator.read permissions to operator.write permissions by sending read-scoped requests through the gateway authentication route. This vulnerability enables unauthorized write access to runtime operations, potentially allowing attackers to modify system configurations and execute administrative functions. The issue affects the authentication and authorization controls within the gateway plugin component.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42429
https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5
https://github.com/openclaw/openclaw/security/advisories/GHSA-4f8g-77mw-3rxc
https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-gateway-plugin-http-authentication
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
