CVE-2026-32051: Openclaw

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.

Affected products

  • Openclaw Openclaw: before 2026.3.1 (fixed in 2026.3.1)

Published 2026-03-21. Last modified 2026-06-17.