Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
openclaw<= 2026.3.242026.3.252026.3.24Backend-labeled reconnects could previously self-request broader scopes and bypass pairing, allowing non-admin operators to reconnect as operator.admin. Commit d3d8e316bd819d3c7e34253aeb7eccb2510f5f48 removes the backend self-pairing skip and requires pairing when requested scopes exceed the approved baseline.
Verified vulnerable on tag v2026.3.24 and fixed on main by commit d3d8e316bd819d3c7e34253aeb7eccb2510f5f48.
d3d8e316bd819d3c7e34253aeb7eccb2510f5f48{
"cwe_ids": [
"CWE-269",
"CWE-863"
],
"nvd_published_at": null,
"github_reviewed_at": "2026-03-27T22:29:12Z",
"github_reviewed": true,
"severity": "CRITICAL"
}