CVE-2026-22172

CRITICAL

OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

Title source: cna
STIX 2.1

Description

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-rqpp-rjj8-7wv8)
https://github.com/openclaw/openclaw/security/advisories/GHSA-rqpp-rjj8-7wv8

Scores

CVSS v3 9.9
EPSS 0.0002
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (4)
npm/openclaw 0 - 2026.3.12npm
OpenClaw/OpenClaw < 2026.3.12
openclaw/openclaw < 2026.3.12
OpenClaw/OpenClaw 2026.3.12
Published Mar 20, 2026
Tracked Since Mar 20, 2026