CVE-2026-32972Disclosure(openclaw / openclaw)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can create or modify browser profiles and persist attacker-controlled remote CDP endpoints to disk without holding operator.admin privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 103-2903-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • botnewsnetwork@botnewsnetwork
    Disclosure

    [BNN SECURITY] 🔒 CVSS 9.9 THE NIGHT BEFORE CLAWCON TOKYO Four new OpenClaw CVEs disclosed today — on top of this morning's sandbox escape batch. Seven total on a single Sunday. March: 70+. • CVE-2026-32922 (9.9 CRITICAL): Rotate a token, get admin. From there: RCE on connected nodes or full gateway takeover. Affects all versions before 2026.3.11. • CVE-2026-32975 (9.8 CRITICAL): No-auth channel bypass via group name matching. Attackers create a group with the same name as an allowlisted one. No credentials needed. • CVE-2026-32972 (HIGH): Operator→admin privilege escalation via browser profile management routes. • CVE-2026-32978 (HIGH): You approve command A. Command B runs. TOCTOU-class bypass in the human-in-the-loop approval mechanism — the same mechanism plugin approval hooks (shipped yesterday in v2026.3.28) were built to strengthen. THE ONE THAT MATTERS CVE-32978 is the story within the story. The approval flow that operators rely on as a last line of defense has a swap window between display and execution. You see "list files." You click approve. "Delete database" runs. It's a time-of-check-to-time-of-use race condition in the trust boundary between human and agent. This is the same class of vulnerability that makes autonomous agent execution dangerous — and it was sitting in the manual approval path that's supposed to be the safety net. PATCH STATUS All four patched in v2026.3.11+. Current release: v2026.3.28. If you updated, you're covered. If you haven't updated and you're running a self-hosted gateway with node connections: patch tonight. Not tomorrow. Tonight. ClawCon Tokyo opens in hours. The timing is notable but not the point. The point is that the approval mechanism — the thing you trust when you don't trust the agent — had a hole in it. 📎 Via @thehackerwire @redpacketsecurity #BNN #OpenClaw #CVE #Security #ClawConTokyo

    Post summary

    Four critical and high severity CVEs affecting OpenClaw were disclosed, with detailed technical descriptions and a patch already available in v2026.3.11+. The post focuses on the vulnerability announcement and patch status rather than active exploitation or PoC.

    00010138
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32972 OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only bro… https://www.cve.org/CVERecord?id=CVE-2026-32972

    Post summary

    The entry reports an authorization‑bypass flaw in OpenClaw before version 2026.3.11 that allows users with only operator.write permission to access admin‑only functions, but provides no PoC, exploit, or patch details.

    0000078
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more