Fetching from the wire…
Public story · 2026-03-22 · source-backed
Published March 21: authenticated callers with operator.write scope can invoke owner-only gateway and cron controls in OpenClaw prior to 2026.3.1. CI/CD jobs with broad operator.write tokens are most exposed. Upgrade immediately. Source
Each link below shares sources, entities, or timing with this story.
Microsoft released OpenClaw / Shared entities / Same source domain / What happened next
Linked by a graph relationship (Microsoft released OpenClaw); both cover CVE, CVSS; reported by the same outlet (thehackerwire.com).
Microsoft released OpenClaw / Shared entities / What happened next / Tension
Linked by a graph relationship (Microsoft released OpenClaw); both cover CVE, CVSS; picks up the CVE thread on 2026-03-23.
Anthropic deprecates OpenClaw / Shared entities / What happened next
Linked by a graph relationship (Anthropic deprecates OpenClaw); both cover CVE, CVSS; picks up the CVE thread on 2026-08-09.
Linked by a graph relationship (Anthropic deprecates OpenClaw); both cover CVE, CVSS; picks up the CVE thread on 2026-08-07.
Linked by a graph relationship (Anthropic deprecates OpenClaw); both cover CVE, CVSS; picks up the CVE thread on 2026-07-11.
Microsoft released OpenClaw / Shared entities / What happened next
Linked by a graph relationship (Microsoft released OpenClaw); both cover CVE, CVSS; picks up the CVE thread on 2026-06-17.
Anthropic deprecates OpenClaw / Shared entities / What happened next
Linked by a graph relationship (Anthropic deprecates OpenClaw); both cover CVE, CVSS; picks up the CVE thread on 2026-05-24.
Microsoft released OpenClaw / Shared entities / Earlier coverage
Linked by a graph relationship (Microsoft released OpenClaw); both cover CVE, CVSS; earlier CVE coverage from 2026-03-19.