


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privilege escalati…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:20
Source:
nvd.nist.gov
Identity & Access, Web Technologies
OpenClaw versions before 2026.3.31 contain an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that enables privilege escalation to operator.admin level. The vulnerability occurs when attackers declare operator scopes on non-Control-UI clients, causing self-declared scopes to persist on identity-bearing authentication paths. This allows unauthorized privilege escalation through the trusted-proxy authentication mechanism. The issue has been addressed in version 2026.3.31 with proper scope clearing implementation.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41404
https://github.com/openclaw/openclaw/commit/8b88b927cb0747ad24d95b07d35682bf85dc5b0e
https://github.com/openclaw/openclaw/security/advisories/GHSA-g374-mggx-p6xc
https://www.vulncheck.com/advisories/openclaw-operator-admin-privilege-escalation-via-trusted-proxy-authentication
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
