CVE-2026-22172Disclosure(openclaw / openclaw)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 5 mentions (2026-03-20); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline13 mentions / 7d
01345Mentions · 2026-03-20: 5Mentions · 2026-03-22: 2Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-03-30: 1Mentions · 2026-04-02: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-20: 5Technical Details · 2026-03-22: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-02: 103-2003-2203-2303-2403-2603-3004-02
Signal classification3 categories
Disclosure
861.5%
Patch
323.1%
General
215.4%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-205
Disclosure3General1Patch1
2026-03-222
Disclosure2
2026-03-232
Disclosure1Patch1
2026-03-241
Disclosure1
2026-03-261
General1
2026-03-301
Patch1
2026-04-021
Disclosure1
Full discourse13 posts
  • RapidClaw@ClawRapid
    Disclosure

    The CVSS 9.9 (CVE-2026-22172): Missing scope validation. Low-privilege users could declare admin scopes during WebSocket handshake. Zero authorization verification. One call = full control.

    Post summary

    The text reports a high‑severity vulnerability (CVE-2026-22172) that allows low‑privilege users to acquire admin privileges via WebSocket handshake, but it provides no PoC, exploit code, or patch information.

    1000046
    13 followersView on X
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    @shun3ai openclaw patched a 9.9 cvss vuln (cve-2026-22172) — websocket clients could just tell the server 'i'm admin' and it believed them. no exploit needed. just ask. 9 cves in 4 days total. update to 2026.3.12 now. source: https://openclawai.io/blog/openclaw-cve-flood-nine-vulnerabilities-four-days-march-2026

    Post summary

    OpenClaw released a patch for CVE‑2026‑22172, a high‑severity flaw allowing websocket clients to impersonate administrators, as part of nine new CVEs disclosed over four days.

    0001056
    147 followersView on X
  • Guang Gong@oldfresher
    General

    2/ The acceptance standard is inconsistent. CVE-2026-22172 (CVSS 9.9) requires a Gateway token. CVE-2026-32051 (CVSS 8.8) requires operator.write scope. This report requires zero authentication — only group chat membership. Why the different bar?

    Post summary

    The tweet contrasts authentication requirements across two CVEs, noting inconsistent acceptance standards, but provides no evidence of PoC, exploit, or patch availability.

    000011.3K
    4.3K followersView on X
  • Kevin Poireault@kpoireault
    Disclosure

    🔎 GitHub advisory: https://github.com/openclaw/openclaw/security/advisories/GHSA-rqpp-rjj8-7wv8 🐞 VulnCheck advisory: https://www.vulncheck.com/advisories/openclaw-scope-elevation-in-websocket-shared-auth-connections 💾 View JSON: https://cveawg.mitre.org/api/cve/CVE-2026-22172

    Post summary

    The post shares links to advisories and the CVE JSON for CVE-2026-22172, indicating the vulnerability has been disclosed but lacks details on PoC, exploit, or active exploitation.

    0001064
    1.6K followersView on X
  • Kevin Poireault@kpoireault
    Patch

    VulnWatch Monday: CVE-2026-22172 🔓 🦞 Yekai Chen (aka LUOYEcode) has detected a critical vulnerability affecting @openclaw versions prior to 2026.3.12. @VulnCheckAI 🔧 Fix in OpenClaw 2026.3.12. https://t.co/zV94Vfb3Gy

    Post summary

    The tweet reports a critical vulnerability (CVE-2026-22172) affecting OpenClaw prior to version 2026.3.12 and announces that the issue will be fixed in OpenClaw 2026.3.12.

    1000067
    1.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-22172 — CVSS 9.9/10 ██████████ OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/CNdZwAyrAc

    Post summary

    OpenClaw versions prior to 2026.3.12 suffer from a critical authorization bypass via the WebSocket connect path (CVSS 9.9/10). A patch has already been released.

    1000037
    7 followersView on X
  • Agentic Yield@AgenticYield
    Disclosure

    CVE-2026-22172 (CVSS 9.9 Critical): OpenClaw versions before 2026.3.12 let shared-token connections self-declare elevated scopes — no server-side binding check. If you're running OpenClaw, check your version now. https://advisories.gitlab.com/pkg/npm/openclaw/GHSA-x49q-fhhm-r9jf/

    Post summary

    An advisory for CVE‑2026‑22172 in OpenClaw outlines a critical flaw that lets shared‑token connections self‑declare elevated scopes, urging users to verify their version, without mentioning exploits or additional mitigation details.

    0000060
    15 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `OpenClaw` critical vulnerability (CVE-2026-22172) allows WebSocket shared-auth connections to self-declare elevated scopes. Review your deployments for risk. #OpenClaw #AuthBypass #WebSockets https://www.pulsepatch.io/posts/cve-2026-22172-openclaw-websocket-privilege-escalation

    Post summary

    The post announces a critical OpenClaw vulnerability (CVE‑2026‑22172) that lets WebSocket shared‑auth connections grant themselves higher privileges, urging users to audit their deployments.

    0000036
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22172 OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated co… https://www.cve.org/CVERecord?id=CVE-2026-22172

    Post summary

    CVE-2026-22172 is an authorization bypass flaw in OpenClaw's WebSocket connect path, impacting versions prior to 2026.3.12.

    0000089
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-22172 OpenClaw WebSocket Authorization Bypass Enabling Unauthorized Admin Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22172

    Post summary

    The text briefly references CVE‑2026‑22172, indicating an authorization bypass in OpenClaw’s WebSocket implementation, but provides no PoC, exploit details, patches, or evidence of active exploitation.

    0000061
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22172 - Critical OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-dec... https://www.thehackerwire.com/vulnerability/CVE-2026-22172/ https://t.co/mwRnHVOqte

    Post summary

    This tweet announces a critical authorization bypass vulnerability (CVE-2026-22172) in OpenClaw versions below 2026.3.12, affecting WebSocket connections; no exploit, patch, or active exploitation details are provided.

    0000062
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22172: CRITICAL] OpenClaw versions < 2026.3.12 have an authorization bypass flaw, letting attackers claim elevated scopes like operator.admin through self-declared connections.#cve,CVE-2026-22172,#cybersecurity https://cvefind.com/CVE-2026-22172

    Post summary

    The tweet announces a critical authorization bypass flaw in OpenClaw versions below 2026.3.12, enabling attackers to elevate privileges to operator.admin via self-declared connections.

    0000055
    604 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-22172: OpenClaw < 2026.3.12 - Scope Ele... WebSocket auth bypass lets any low-priv user self-declare admin scopes and own the gateway - classic missing server-sid... https://zerodaysignal.com/vulnerability/CVE-2026-22172 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses a WebSocket authentication bypass in OpenClaw 2026.3.12 that allows low‑privileged users to self‑assign admin privileges and control the gateway.

    0000063
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more