OpenClaw versions prior to 2026.3.22 contain a settings reconciliation vulnerability that allows attackers to bypass access control denials by exploiting improper handling of empty allowlists. During the reconciliation process, explicitly configured empty allowlists are treated as unset values, causing the system to silently restore previously revoked permissions and undo intended deny-all access controls. This vulnerability affects the access control mechanisms that are fundamental to the product's security posture. The vulnerability has a CVSS v3.1 score of 6.5 (Medium severity) with a network-based attack vector requiring no authentication or user interaction, making it relatively easy to exploit remotely. The impact is limited to partial confidentiality and integrity compromise without availability impact, suggesting attackers could gain unauthorized access to restricted resources or modify certain system configurations. There is no evidence of active exploitation in the wild at this time, and the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. The EPSS score of 0.0003 indicates a very low probability of exploitation within the next 30 days. Community attention appears minimal given the inactive status on vulnerability hotlists, though organizations running affected OpenClaw versions should prioritize updating to version 2026.3.22 or later as part of routine patch management.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.22CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.22CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.