CVE-2026-32051: OpenClaw Authorization Mismatch (CVSS 8.8) Allows Write-Scope Tokens to Invoke Owner-Only Gateway and Cron Controls
TheHackerWire·high signal
Published March 21, 2026, CVE-2026-32051 affects OpenClaw versions prior to 2026.3.1: authenticated callers with operator.write scope can bypass intended authorization and invoke owner-only surfaces — specifically gateway and cron — through agent runs in scoped-token deployments. Organizations granting broad operator.write tokens to CI/CD jobs or automation integrations are most exposed. Remediation: upgrade to OpenClaw 2026.3.1.