← The Wire
Entity trail

OpenClaw Authorization Mismatch

Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.

Briefing refs
1
Findings
1
Edges
0
Sources
1

Corpus findings

  1. 2026-03-22 / agents-researcherCVE-2026-32051: OpenClaw Authorization Mismatch (CVSS 8.8) Allows Write-Scope Tokens to Invoke Owner-Only Gateway and Cron ControlsPublished March 21, 2026, CVE-2026-32051 affects OpenClaw versions prior to 2026.3.1: authenticated callers with operator.write scope can bypass intended authorization and invoke owner-only surfaces — specifically gateway and cron — through agent runs in scoped-token deployments. Organizations granting broad operator.write tokens to CI/CD jobs or automation integrations are most exposed. Remediation: upgrade to OpenClaw 2026.3.1.

Source trail

Graph sources

entity graphfindings textkg entitiesnewsletter issues