CVE-2026-35669 is a privilege escalation vulnerability affecting OpenClaw versions prior to 2026.3.25, wherein gateway-authenticated plugin HTTP routes incorrectly assign operator.admin runtime scope to all callers regardless of their actual permissions. This flaw allows attackers to bypass scope boundaries and gain unauthorized administrative privileges within the system. The vulnerability carries a HIGH severity rating with a CVSS score of 8.8, indicating significant risk across multiple impact dimensions. The attack requires network access and low privileges to initiate but demands no user interaction, and affects core system confidentiality, integrity, and availability with unrestricted scope impact. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms this is a straightforward attack with high consequences. Exploitation status indicates the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code appears to be in active circulation. The EPSS score of 0.00044 suggests low probability of exploitation in the wild, though the FAUCET Risk Score of 52.0 indicates moderate organizational concern. Community attention remains minimal at this time, with the vulnerability classified as inactive on exploitation monitoring lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.25CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.25CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.