Report: CVE-2026-42429 - OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication - Guide

Report: CVE-2026-42429 - OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication - Guide

CVE ID :CVE-2026-42429 Published : April 28, 2026, 7:37 p.m. | 1 hour, 2 minutes ago Description :OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator.read requests into runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
April 28, 2026
Impact: privilege escalation