Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35669

31
FAUCET Score

CVE-2026-35669 is a privilege escalation vulnerability affecting OpenClaw versions prior to 2026.3.25, wherein gateway-authenticated plugin HTTP routes incorrectly assign operator.admin runtime scope to all callers regardless of their actual permissions. This flaw allows attackers to bypass scope boundaries and gain unauthorized administrative privileges within the system. The vulnerability carries a HIGH severity rating with a CVSS score of 8.8, indicating significant risk across multiple impact dimensions. The attack requires network access and low privileges to initiate but demands no user interaction, and affects core system confidentiality, integrity, and availability with unrestricted scope impact. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms this is a straightforward attack with high consequences. Exploitation status indicates the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code appears to be in active circulation. The EPSS score of 0.00044 suggests low probability of exploitation in the wild, though the FAUCET Risk Score of 52.0 indicates moderate organizational concern. Community attention remains minimal at this time, with the vulnerability classified as inactive on exploitation monitoring lists.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.3.25CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.3.25CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 9th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-qm2m-28pf-hgjwhigh

OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers

Mar 27, 2026

References

github.com / openclaw/openclaw/commit/ec2dbcff9afd8a52e00de054b506c91726d9fbbe
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-qm2m-28pf-hgjw
Vendor Advisory
vulncheck.com / advisories/openclaw-privilege-escalation-via-gateway-plugin-http-authentication-scope
Third Party Advisory