CVE-2026-32916Disclosure(openclaw / openclaw)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke runtime.subagent methods to perform privileged gateway actions including session deletion and agent execution.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-31); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-03-31: 1Active Exploitation · 2026-04-09: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-09: 103-3104-0104-09
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure2
2026-04-011
Disclosure1
2026-04-091
Active Exploitation1
Full discourse4 posts
  • Everything AI@everythingLLM
    Active Exploitation

    A vulnerability in the AI agent everyone's running gave attackers silent admin access to 180,000 systems. No one noticed. The flaw is CVE-2026-32916, a CVSS 9.4 vulnerability in OpenClaw, the open-source AI agent that connects to your email, terminal, and messaging apps. The vulnerability lived in OpenClaw's plugin subagent routes. When a third-party plugin handled requests, it funneLED them through a synthetic operator client carrying full administrative permissions. Those routes did not check whether the requester was authenticated. Any actor on the network could send requests directly to plugin-owned endpoints and have them executed with admin privileges. That meant deleting user sessions, executing arbitrary agent actions, and potentially chaining into whatever services the agent had access to. The attack was silent. No alerts, no user-facing indicators. The agent just did what it was told by someone who should never have been able to talk to it. OpenClaw has roughly 180,000 developers building on it. The vulnerable versions were 2026.3.7 through 2026.3.10. The fix landed in version 2026.3.11 on March 31. If you are running those versions with third-party plugins, assume compromise today. Audit your connected services for unauthorized activity. This is not just an OpenClaw story. It is a preview of what happens when we give AI agents broad system access and then secure the plumbing the same way we secured web apps in 2008. A compromised web app leaks data. A compromised AI agent with terminal access and email permissions can actively do damage, and it will do so quietly. The scarier question is what similar flaws exist in closed-source agent platforms where security researchers cannot even look at the code.

    Post summary

    The post claims CVE‑2026‑32916 was actively exploited, giving attackers silent admin access to roughly 180,000 OpenClaw installations, while also noting a patch has been released.

    10020148
    46 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32916 - Critical OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with bro... https://www.thehackerwire.com/vulnerability/CVE-2026-32916/ https://t.co/n3HaZ1XkwP

    Post summary

    A critical CVE-2026-32916 affecting OpenClaw versions 2026.3.7 to 2026.3.10 is disclosed, describing an authorization bypass that allows plugin subagent to execute gateway methods. No patches, active exploitation, or PoC details are referenced.

    0001065
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32916: OpenClaw 2026.3.7 < 2026.3.11 - ... Synthetic admin clients with broad scopes = instant root via unauthenticated plugin routes - classic privilege escalati... https://zerodaysignal.com/vulnerability/CVE-2026-32916 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑32916 is a newly disclosed privilege‑escalation vulnerability in OpenClaw versions prior to 2026.3.11, enabled by unauthenticated plugin routes; a zero‑day signal link is provided for more details.

    0000064
    194 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32916 OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic ope… https://www.cve.org/CVERecord?id=CVE-2026-32916

    Post summary

    The post announces an authorization bypass vulnerability (CVE‑2026‑32916) in OpenClaw versions 2026.3.7 through 2026.3.10, noting that later releases (e.g., 2026.3.11) should mitigate the issue.

    00000138
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more