CVE-2026-22172
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that al
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.
CRITICAL · CVSS 9.9
EPSS 0.00021
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0