top of page
perceptive_background_267k.jpg

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator…

Published:

27 april 2026 om 22:00:00

Alert date:

28 april 2026 om 21:20:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies

OpenClaw versions before 2026.4.8 contain a critical privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism. The flaw allows attackers to escalate operator.read permissions to operator.write permissions by sending read-scoped requests through the gateway authentication route. This vulnerability enables unauthorized write access to runtime operations, potentially allowing attackers to modify system configurations and execute administrative functions. The issue affects the authentication and authorization controls within the gateway plugin component.

Technical details

Mitigation steps:

Affected products:

OpenClaw

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page