OpenClaw
OpenClaw
| Version / range | Status | Type |
|---|---|---|
| 0 to before 2026.8.1 | affected | semver |
| 2026.8.1 | unaffected | semver |
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and auth-profile settings to redirect traffic and bypass administrative access controls.
Risk score
5.3
CVSS 4.0
OpenClaw
| Version / range | Status | Type |
|---|---|---|
| 0 to before 2026.8.1 | affected | semver |
| 2026.8.1 | unaffected | semver |
5.3
CVSS 4.0
5.4
CVSS 3.1