HarborGuard / CVE
Back to search
HIGHCVE-2026-45006Published Modified CNA VulnCheck

CVE-2026-45006: OpenClaw < 2026.4.23 - Unsafe Config Mutation via Gateway Tool Denylist Bypass

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete denylist protection. Attackers can persist malicious config modifications affecting command execution, network behavior, credentials, and operator policies that survive restart.

Metrics

CVSS v4.0
7.7
Severity
HIGH
Fixed in
2026.4.23
Affected Products
1

Fix available

2026.4.23
Patch commits
Affected packages
  • OpenClaw / OpenClaw
    < 2026.4.23 (from 0)
    Fixed in 2026.4.23
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N