


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-on…
Published:
28 maart 2026 om 23:00:00
Alert date:
29 maart 2026 om 14:05:44
Source:
nvd.nist.gov
Identity & Access, Web Technologies
OpenClaw versions before 2026.3.11 contain an authorization bypass vulnerability that allows authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. This vulnerability enables attackers to create or modify browser profiles and persist attacker-controlled remote CDP endpoints to disk without requiring operator.admin privileges. The flaw represents a privilege escalation issue where lower-privileged users can perform administrative functions they should not have access to.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32972
https://github.com/openclaw/openclaw/security/advisories/GHSA-vmhq-cqm9-6p7q
https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-browser-profile-management-via-browser-request
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
