CVE-2026-32051Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-21); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-03-21: 4Mentions · 2026-03-22: 3Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-22: 3Technical Details · 2026-03-21: 3Technical Details · 2026-03-22: 3Technical Details · 2026-03-26: 103-2103-2203-26
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-214
Disclosure4
2026-03-223
Patch3
2026-03-261
Disclosure1
Full discourse8 posts
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    📰 dev news today: 1. 🔥 claude code channels — control your coding agent from telegram & discord 2. ⚡ claude code opus 4.6 — default output bumped to 64k tokens, 128k max 3. 🚀 ai agent tool-use patterns that actually work in production 4. 🔒 openclaw cve-2026-32051 — cvss 8.8 auth mismatch, patch to v2026.3.1 5. 🛡️ claude code cve-2026-33068 — workspace trust dialog bypass, fixed in v2.1.53 [1/7]

    Post summary

    The announcement lists two CVEs with technical details and notes that official patches are available, highlighting vulnerability fixes rather than exploitation.

    60040115
    143 followersView on X
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    📰 dev news today: 1. 🔥 claude code channels — control your coding agent from telegram & discord 2. ⚡ claude code opus 4.6 — default output bumped to 64k tokens, 128k max 3. 🚀 ai agent tool-use patterns that actually work in production 4. 🔒 openclaw cve-2026-32051 — cvss 8.8 auth mismatch, patch to v2026.3.1 5. 🛡️ claude code cve-2026-33068 — workspace trust dialog bypass, fixed in v2.1.53 [1/7]

    Post summary

    The note announces two CVEs, lists their technical details, and supplies the corresponding patch versions, indicating a focus on vulnerability mitigation.

    10050132
    143 followersView on X
  • Guang Gong@oldfresher
    Disclosure

    2/ The acceptance standard is inconsistent. CVE-2026-22172 (CVSS 9.9) requires a Gateway token. CVE-2026-32051 (CVSS 8.8) requires operator.write scope. This report requires zero authentication — only group chat membership. Why the different bar?

    Post summary

    The message discusses inconsistencies in acceptance requirements for CVE-2026-22172 and CVE-2026-32051, providing specific vulnerability details such as CVSS scores and authentication scopes, but without any mention of exploitation, patches, or PoCs.

    000011.3K
    4.3K followersView on X
  • Shin0221 🇯🇵 Indie Hacker🦞@0xShin0221
    Patch

    🔒 openclaw cve-2026-32051 — cvss 8.8 auth mismatch in versions <2026.3.1 operator.write-scoped callers can invoke owner-only tools: gateway, cron patch now if you run openclaw with scoped tokens in ci/cd src: https://www.thehackerwire.com/openclaw-authorization-mismatch-cve-2026-32051/ [5/7]

    Post summary

    The post highlights CVE-2026-32051, an authentication mismatch vulnerability in OpenClaw with a CVSS score of 8.8, and urges users to apply a patch immediately for CI/CD environments using scoped tokens.

    0000040
    143 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32051 - High OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including ga... https://www.thehackerwire.com/vulnerability/CVE-2026-32051/ https://t.co/hYo3tssnb5

    Post summary

    CVE-2026-32051 is disclosed for OpenClaw before version 2026.3.1, exposing an authorization mismatch that lets authenticated users with operator.write scope invoke owner‑only tool surfaces.

    0000052
    142 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-32051 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32051-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32051 #openclaw #

    Post summary

    A CVE alert for CVE-2026-32051 (OpenClaw) is posted with a link to a security site, but no further details are provided in the text.

    0000092
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32051 OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only t… https://www.cve.org/CVERecord?id=CVE-2026-32051

    Post summary

    CVE-2026-32051 exposes an authorization mismatch in OpenClaw, allowing authenticated users with operator.write scope to call owner‑only functions; no exploitation, patch, or PoC details are provided.

    0000084
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32051: HIGH] OpenClaw pre-2026.3.1 has an authorization mismatch flaw, letting authenticated users with operator.write scope access owner-only tool surfaces like gateway and cron, enabling unauthor...#cve,CVE-2026-32051,#cybersecurity https://cvefind.com/CVE-2026-32051

    Post summary

    The tweet announces a high‑severity authorization mismatch flaw in OpenClaw pre‑2026.3.1 that allows authenticated users with an operator.write scope to access restricted tools such as gateway and cron.

    0000063
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more