CVE-2026-35669Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope boundary bypass to gain elevated privileges and perform unauthorized administrative actions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-648

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-11)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-10: 2Mentions · 2026-04-11: 3Patch / Workaround · 2026-04-11: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 304-1004-11
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure2
2026-04-113
Disclosure2Patch1
Full discourse5 posts
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 TODAY'S TOP 3 AGENT THREATS — 1. reconnect privilege escalation (CVE-2026-35663) non-admin operators self-grant admin privileges during backend reconnect by bypassing pairing requirements 2. scope boundary bypass via gateway routes (CVE-2026-35669) plugin HTTP routes incorrectly mint operator.admin scope regardless of caller permissions, handing attackers elevated privileges 3. session reset access control failure (CVE-2026-35660) attackers with operator.write can reset admin sessions via /reset endpoint, hijacking administrative control is your agent on the list? → http://agentcop.live #AgentSecurity #CVE

    Post summary

    The post announces three new CVEs affecting agent software, detailing privilege escalation, scope bypass, and access control flaws, but includes no PoC, exploit, patch, or evidence of active exploitation.

    0000046
    6 followersView on X
  • Sable Agere@SableAgere
    Patch

    CVE-2026-35669. CVSS 8.8. 7th pairing vulnerability in 7 weeks. Authenticated attackers can bypass scope boundaries in OpenClaw. This is not a bug — it's a systemic design flaw in permission handling. If you're running OpenClaw online, patch. Now.

    Post summary

    The snippet alerts that CVE‑2026‑35669 is a high‑severity design flaw in OpenClaw allowing authenticated attackers to bypass scope boundaries and urges users to apply the patch immediately.

    0000051
    9 followersView on X
  • Sable Agere@SableAgere
    Disclosure

    New CVE — CVE-2026-35669. CVSS 8.8. Privilege escalation via scope boundary bypass. 7th pairing-related vulnerability in 7 weeks. This isn't a bug. It's a systemic design flaw. If you're running OpenClaw online and haven't patched, you're exposed.

    Post summary

    A new high‑score CVE (CVE-2026-35669) is disclosed, highlighting a privilege escalation flaw that bypasses scope boundaries and threatens users of OpenClaw online who have not applied the necessary patch.

    0000059
    9 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35669 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope… https://www.cve.org/CVERecord?id=CVE-2026-35669

    Post summary

    The text discloses a privilege escalation vulnerability in OpenClaw <2026.3.25, where gateway‐authenticated plugin HTTP routes improperly grant operator.admin runtime scope.

    00000144
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-35669: HIGH] Warning! OpenClaw has a critical privilege escalation flaw that lets attackers bypass scopes and gain unauthorized high-level access by exploiting a vulnerability in its gateway-authen...#cve,CVE-2026-35669,#cybersecurity https://cvefind.com/CVE-2026-35669

    Post summary

    The tweet announces a high‑severity privilege escalation vulnerability in OpenClaw but provides no PoC, exploit code, or mitigation details.

    0000067
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more