Untriaged
Permalink
CVE-2026-32972
7.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): LOW
OpenClaw < 2026.3.11 - Authorization Bypass in Browser Profile Management via browser.request
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can create or modify browser profiles and persist attacker-controlled remote CDP endpoints to disk without holding operator.admin privileges.
References
-
GitHub Security Advisory (GHSA-vmhq-cqm9-6p7q) third-party-advisory
Affected products
OpenClaw
- <2026.3.11
- ==2026.3.11
Package maintainers
-
@chrisportela Chris Portela <chris@chrisportela.com>