CVE-2026-102807: OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket
OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a valid token with operator.read scope. The flaw can then be used to invoke MCP App tools that require operator.write scope.
What access path is involved in the bypass?
The attacker obtains a standalone ticket through the mcp.app.view method and redeems that ticket at the MCP app view endpoint. The authorization check at that flow does not properly prevent state-changing tool execution.
What versions should be treated as affected?
OpenClaw versions before 2026.9.4 are affected. Upgrading to 2026.9.4 or later addresses the stated vulnerable version range.