<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:47:46 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32916 — OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32916</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the plugin subagent runtime dispatched gateway methods through a synthetic operator client that always carried broad administrative scopes. Plugin-owned HTTP routes using `auth: &amp;#34;plugin&amp;#34;` could therefore trigger admin-only gateway actions without normal gateway authorization.&lt;/p&gt;
&lt;p&gt;## Impact
This is a critical authorization bypass. An external unauthenticated request to a plugin-owned route could reach privileged subagent runtime methods and perform admin-only gateway actions such as deleting sessions, reading session data, or triggering agent execution.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;gt;= 2026.3.7, &amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The new plugin subagent runtime preserved neither the original caller&amp;#39;s auth context nor least-privilege scope. Instead, it executed gateway dispatches through a fabricated operator client with administrative scopes, which was reachable from plugin-owned routes that intentionally bypass normal gateway auth so plugins can perform their own webhook verification.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now preserves real authorization boundaries for plugin subagent calls instead of dispatching them through synthetic admin scopes. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the plugin subagent runtime dispatched gateway methods through a synthetic operator client that always carried broad administrative scopes. Plugin-owned HTTP routes using `auth: &amp;#34;plugin&amp;#34;` could therefore trigger admin-only gateway actions without normal gateway authorization.&lt;/p&gt;
&lt;p&gt;## Impact
This is a critical authorization bypass. An external unauthenticated request to a plugin-owned route could reach privileged subagent runtime methods and perform admin-only gateway actions such as deleting sessions, reading session data, or triggering agent execution.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;gt;= 2026.3.7, &amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The new plugin subagent runtime preserved neither the original caller&amp;#39;s auth context nor least-privilege scope. Instead, it executed gateway dispatches through a fabricated operator client with administrative scopes, which was reachable from plugin-owned routes that intentionally bypass normal gateway auth so plugins can perform their own webhook verification.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now preserves real authorization boundaries for plugin subagent calls instead of dispatching them through synthetic admin scopes. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32916</guid>
    </item>
    <item>
      <title>cnvd-2026-17183</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-17183</link>
      <description>cnvd-2026-17183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-17183</guid>
    </item>
    <item>
      <title>EUVD-2026-329465</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329465</link>
      <description>EUVD-2026-329465</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329465</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32916</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32916</link>
      <description>&lt;p&gt;OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke runtime.subagent methods to perform privileged gateway actions including session deletion and agent execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke runtime.subagent methods to perform privileged gateway actions including session deletion and agent execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32916</guid>
    </item>
    <item>
      <title>GHSA-xw77-45gv-p728 — OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xw77-45gv-p728</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the plugin subagent runtime dispatched gateway methods through a synthetic operator client that always carried broad administrative scopes. Plugin-owned HTTP routes using `auth: &amp;#34;plugin&amp;#34;` could therefore trigger admin-only gateway actions without normal gateway authorization.&lt;/p&gt;
&lt;p&gt;## Impact
This is a critical authorization bypass. An external unauthenticated request to a plugin-owned route could reach privileged subagent runtime methods and perform admin-only gateway actions such as deleting sessions, reading session data, or triggering agent execution.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;gt;= 2026.3.7, &amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The new plugin subagent runtime preserved neither the original caller&amp;#39;s auth context nor least-privilege scope. Instead, it executed gateway dispatches through a fabricated operator client with administrative scopes, which was reachable from plugin-owned routes that intentionally bypass normal gateway auth so plugins can perform their own webhook verification.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now preserves real authorization boundaries for plugin subagent calls instead of dispatching them through synthetic admin scopes. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
In affected versions of `openclaw`, the plugin subagent runtime dispatched gateway methods through a synthetic operator client that always carried broad administrative scopes. Plugin-owned HTTP routes using `auth: &amp;#34;plugin&amp;#34;` could therefore trigger admin-only gateway actions without normal gateway authorization.&lt;/p&gt;
&lt;p&gt;## Impact
This is a critical authorization bypass. An external unauthenticated request to a plugin-owned route could reach privileged subagent runtime methods and perform admin-only gateway actions such as deleting sessions, reading session data, or triggering agent execution.&lt;/p&gt;
&lt;p&gt;## Affected Packages and Versions
- Package: `openclaw` (npm)
- Affected versions: `&amp;gt;= 2026.3.7, &amp;lt; 2026.3.11`
- Fixed in: `2026.3.11`&lt;/p&gt;
&lt;p&gt;## Technical Details
The new plugin subagent runtime preserved neither the original caller&amp;#39;s auth context nor least-privilege scope. Instead, it executed gateway dispatches through a fabricated operator client with administrative scopes, which was reachable from plugin-owned routes that intentionally bypass normal gateway auth so plugins can perform their own webhook verification.&lt;/p&gt;
&lt;p&gt;## Fix
OpenClaw now preserves real authorization boundaries for plugin subagent calls instead of dispatching them through synthetic admin scopes. The fix shipped in `openclaw@2026.3.11`.&lt;/p&gt;
&lt;p&gt;## Workarounds
Upgrade to `2026.3.11` or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xw77-45gv-p728</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0711 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0711</guid>
    </item>
  </channel>
</rss>
