Vulnerabilities
Report: CVE-2026-42429 - OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication - Guide
CVE ID :CVE-2026-42429 Published : April 28, 2026, 7:37 p.m. | 1 hour, 2 minutes ago Description :OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator.read requests into runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Impact:
privilege escalation