PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32916 OpenClaw CVE debrief

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. This vulnerability allows remote unauthenticated requests to plugin-owned routes to invoke runtime.subagent methods to perform privileged gateway actions, including session deletion and agent execution. The affected product is OpenClaw, and the vulnerability class is authorization bypass. The likely operational impact is high, as it allows for unauthorized actions on the system.

Vendor
OpenClaw
Product
Unknown
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-31
Original CVE updated
2026-07-25
Advisory published
2026-03-31
Advisory updated
2026-07-25

Who should care

Users of OpenClaw versions 2026.3.7 before 2026.3.11 should be aware of this vulnerability and take steps to mitigate it. This includes operators, platform administrators, vulnerability management teams, and security teams who are responsible for ensuring the security and integrity of the system.

Technical summary

The vulnerability allows remote unauthenticated requests to plugin-owned routes to invoke runtime.subagent methods to perform privileged gateway actions, including session deletion and agent execution. This is due to plugin subagent routes executing gateway methods through a synthetic operator client with broad administrative scopes. The affected product context is OpenClaw versions 2026.3.7 before 2026.3.11. The defensive impact is high, as it requires immediate attention to prevent unauthorized access.

Defensive priority

High

Recommended defensive actions

  • Inventory and check OpenClaw versions 2026.3.7 before 2026.3.11 for potential vulnerability
  • Apply vendor remediation to upgrade to OpenClaw version 2026.3.11 or later
  • Implement compensating controls to monitor and restrict access to plugin-owned routes
  • Monitor for suspicious activity and exception tracking
  • Review and update asset inventory to ensure all affected systems are accounted for
  • Plan and execute a rollback or change window if necessary
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved

Evidence notes

The CVE record was published on 2026-03-31T12:16:28.197Z and was last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus and may not reflect the full scope of the vulnerability. Users should verify the details with the official CVE record and NVD entry for the most accurate and up-to-date information.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T12:16:28.197Z and has not been modified since then. The NVD entry is currently Analyzed.