CVE-2026-43568: OpenClaw 2026.4.5 through 2026.4.9 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint
OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class configuration mutations through the /dreaming endpoint to escalate privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43568?
CVE-2026-43568 is classified as a high severity privilege escalation vulnerability.
How do I fix CVE-2026-43568?
To fix CVE-2026-43568, you should upgrade OpenClaw to version 2026.4.10 or later.
Who is affected by CVE-2026-43568?
CVE-2026-43568 affects users of OpenClaw versions 2026.4.5 through 2026.4.9.
What type of vulnerability is CVE-2026-43568?
CVE-2026-43568 is a privilege escalation vulnerability that allows unauthorized changes to memory dreaming settings.
What are the consequences of CVE-2026-43568?
Exploitation of CVE-2026-43568 may allow an attacker to alter critical system settings and gain elevated permissions.