CVE-2026-42429: OpenClaw < 2026.4.8 - Privilege Escalation via Gateway Plugin HTTP Authentication
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that escalates identity-bearing operator.read requests to runtime operator.write permissions. Attackers can exploit this by sending read-scoped requests through the gateway auth route to gain unauthorized write access to runtime operations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42429?
CVE-2026-42429 is classified as a privilege escalation vulnerability which can lead to unauthorized access and elevated permissions.
How do I fix CVE-2026-42429?
To mitigate CVE-2026-42429, upgrade OpenClaw to version 2026.4.8 or later.
What systems are affected by CVE-2026-42429?
CVE-2026-42429 affects OpenClaw versions prior to 2026.4.8.
What type of vulnerability is CVE-2026-42429?
CVE-2026-42429 is a privilege escalation vulnerability found in the gateway plugin HTTP authentication mechanism.
What does CVE-2026-42429 impact in OpenClaw?
CVE-2026-42429 impacts the authorization controls allowing identity-bearing operator.read requests to escalate to runtime operator.write permissions.