PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32976 OpenClaw CVE debrief

CVE-2026-32976 is an authorization bypass vulnerability in OpenClaw before 2026.3.11. The vulnerability allows channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false. This issue arises from inadequate restrictions on configWrites, enabling unauthorized configuration changes. The affected product is OpenClaw, and the vulnerability class is authorization bypass. The likely operational impact is modification of configuration on target accounts.

Vendor
OpenClaw
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-31
Original CVE updated
2026-07-25
Advisory published
2026-03-31
Advisory updated
2026-07-25

Who should care

Users of OpenClaw before version 2026.3.11 should be aware of this vulnerability and take steps to mitigate it. This includes administrators and users with authorized access to OpenClaw accounts. The vulnerability affects operators, platforms, vulnerability-management, and security teams.

Technical summary

The vulnerability exists in OpenClaw before 2026.3.11, where an authorization bypass allows channel commands to modify protected sibling-account configurations. Specifically, attackers can use commands like /config set channels.<provider>.accounts.<id> to change settings on accounts with configWrites set to false. This issue arises from inadequate restrictions on configWrites, enabling unauthorized configuration changes. The affected product context is OpenClaw, and the defensive impact is high.

Defensive priority

High

Recommended defensive actions

  • Update OpenClaw to version 2026.3.11 or later
  • Restrict channel command execution to authorized users
  • Monitor account configurations for unauthorized changes
  • Implement additional access controls for sensitive configuration settings
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-03-31T12:16:29.470Z and was last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Analyzed. The vulnerability affects OpenClaw before version 2026.3.11, allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false. The evidence is limited, and defenders should verify the affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T12:16:29.470Z and has not been modified since then. The NVD entry is currently Analyzed.