CVE-2026-32051: OpenClaw < 2026.3.1 - Authorization Bypass in Agent Runs via Owner-Only Tool Access
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32051?
CVE-2026-32051 has a high severity rating due to its potential for unauthorized access to sensitive functionalities.
How do I fix CVE-2026-32051?
To fix CVE-2026-32051, update OpenClaw to version 2026.3.1 or later.
What vulnerabilities are associated with CVE-2026-32051?
CVE-2026-32051 is associated with an authorization bypass that allows unauthorized access to owner-only functionalities.
Who is affected by CVE-2026-32051?
CVE-2026-32051 affects all versions of OpenClaw prior to 2026.3.1.
What consequences can result from CVE-2026-32051?
CVE-2026-32051 can lead to unauthorized actions being performed by authenticated users with insufficient permissions.