This advisory has been withdrawn because it is a duplicate of GHSA-rqpp-rjj8-7wv8. This link is maintained to preserve external references.
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.
{
"github_reviewed": true,
"github_reviewed_at": "2026-03-20T17:24:51Z",
"cwe_ids": [
"CWE-862"
],
"severity": "CRITICAL",
"nvd_published_at": "2026-03-20T15:16:15Z"
}