CVE-2026-32976: OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.11 - Compensating control
Prevent/limit use of channel commands that include /config set channels.<provider>.accounts.<id> until the environment is upgraded, since the vulnerability allows protected sibling-account configuration to be modified despite configWrites:false.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32976?
CVE-2026-32976 is considered a high severity vulnerability due to the authorization bypass it enables.
How do I fix CVE-2026-32976?
To fix CVE-2026-32976, upgrade OpenClaw to version 2026.3.11 or later.
What does CVE-2026-32976 affect?
CVE-2026-32976 affects OpenClaw versions prior to 2026.3.11.
What is the nature of the vulnerability in CVE-2026-32976?
CVE-2026-32976 is an authorization bypass vulnerability that allows mutation of protected configurations.
Who is at risk due to CVE-2026-32976?
Attackers with authorized access to OpenClaw versions before 2026.3.11 are at risk of exploiting CVE-2026-32976.