OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended.
The vulnerability results from an incomplete list of cases handled by the heartbeat owner's downgrade detection mechanism (CWE-184 — incomplete list of disallowed inputs). When a local asynchronous background process terminates, the completion event is not intercepted by the aforementioned mechanism. An attacker can provide untrusted completion content to such a process to force a running task to remain in a more privileged context than it should have after the operation completes.
An attacker can obtain a higher privilege level than they are entitled to, which combined with access to the local system can lead to unauthorized access to protected resources or further compromise of the system.
OpenClaw should be updated to version 2026.4.10 or later. The patch is available in the project repository (commit 19a2e9ddb5a8a494abcba812bb11f51075026a27) and described in the vendor's official security advisory (GHSA-g375-h3v6-4873).
OpenClaw in versions from 2026.3.31 (inclusive) to 2026.4.10 (exclusive).
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenclaw
APPOpenclaw2026.3.31 – 2026.4.10 (excl.)
Related vulnerabilities
OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE
OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC
OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox
OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef
OpenClaw: nieweryfikowane metadane hooków eskalowane do kontekstu systemowego