Summary

Vulnerability Name OpenClaw WebSocket Privilege Escalation via Shared Token
Released on March 17, 2026
Affected Component OpenClaw
Affected Version OpenClaw ≤ 2026.3.11
Vulnerability Type Privilege escalation
Exploitation Condition 1. User authentication: required.
2. Precondition: default configurations.
3. Trigger mode: remote. 
Impact Exploitation difficulty: difficult. Regular user privileges are required.
Severity: critical. This vulnerability can result in privilege escalation. 
Official Solution Available

About the Vulnerability

Component Introduction

OpenClaw is an open-source personal AI assistant on GitHub. It interacts via messaging platforms such as WhatsApp, Telegram, and Discord, and supports both local- and cloud-based large language models (LLMs). It provides autonomous execution capabilities such as browser control, device operations, email or file processing, and voice conversations. OpenClaw is designed to serve as a locally resident, actively functional AI assistant for daily automation, productivity enhancement, and developer tasks.

Vulnerability Description

On March 17, 2026, Sangfor FarSight Labs received notification of the privilege escalation vulnerability in OpenClaw, classified as critical in threat level.

Specifically, when OpenClaw authenticates WebSocket connections by using a shared token or password, the server fails to validate or restrict the privilege scopes declared by the client. It directly trusts and accepts the client-declared scopes. This allows users with only a regular shared token or password to illegitimately claim administrator privileges, thereby resulting in privilege escalation.

Affected Versions

The following OpenClaw versions are affected:
OpenClaw ≤ 2026.3.11

Remediation Solutions

Official Solutions

The latest version has been officially released to fix the vulnerability. Affected users are advised to update OpenClaw to v2026.3.11 or later.
Download link: https://github.com/openclaw/openclaw

Temporary Solutions

  1. Disable unused functional modules to reduce attack entry points.
  2. Follow the principle of least privilege to strictly control the scope of permissions for sensitive operations.
  3. Do not expose services to the Internet unless necessary, to limit the access sources to trusted ranges.
  4. Regularly update the system and components to secure versions so that known vulnerabilities can be patched at the earliest opportunity.

Timeline

On March 17, 2026, Sangfor FarSight Labs received notification of the OpenClaw WebSocket privilege escalation vulnerability.
On March 17, 2026, Sangfor FarSight Labs released a vulnerability alert.

Reference

https://github.com/openclaw/openclaw/security/advisories/GHSA-rqpp-rjj8-7wv8

Learn More

Sangfor FarSight Labs researches the latest cyber threats and unknown zero-day vulnerabilities, alerting customers to potential dangers to their organizations, and providing real-time solutions with actionable intelligence. Sangfor FarSight Labs works with other security vendors and the security community at large to identify and verify global cyber threats, providing fast and easy protection for customers.

Listen To This Post

Search

Related Articles

Linux Cryptojacking Could be Secretly Draining Your Server Resources

Date : 26 May 2026
Read Now

GoldFactory Targets Vietnam and Thailand with Mobile Banking Fraud

Date : 12 May 2026
Read Now

LiteLLM SQL Injection (CVE-2026-42208)

Date : 29 Apr 2026
Read Now

See Other Product

Sangfor Omni-Command
Replace your Enterprise NGAV with Sangfor Endpoint Secure
SASE ROI Calculator - Assess Sangfor SASE’s Total Economic Impact
Sangfor Athena XDR - Extended Detection and Response
Athena SASE - Secure Access Service Edge
Sangfor Athena NGFW - Next Generation Firewall