OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical severity
GitHub Reviewed
Published
Mar 26, 2026
in
openclaw/openclaw
•
Updated Mar 27, 2026
Description
Published to the GitHub Advisory Database
Mar 27, 2026
Reviewed
Mar 27, 2026
Last updated
Mar 27, 2026
Summary
Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Affected Packages / Versions
openclaw<= 2026.3.242026.3.252026.3.24Details
Backend-labeled reconnects could previously self-request broader scopes and bypass pairing, allowing non-admin operators to reconnect as
operator.admin. Commitd3d8e316bd819d3c7e34253aeb7eccb2510f5f48removes the backend self-pairing skip and requires pairing when requested scopes exceed the approved baseline.Verified vulnerable on tag
v2026.3.24and fixed onmainby commitd3d8e316bd819d3c7e34253aeb7eccb2510f5f48.Fix Commit(s)
d3d8e316bd819d3c7e34253aeb7eccb2510f5f48References