Vulnerabilities
Report: CVE-2026-22172 - OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections
CVE ID :CVE-2026-22172 Published : March 20, 2026, 3:16 p.m. | 56 minutes ago Description :OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized scopes such as operator.admin and perform admin-only gateway operations. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...