A AegiFlow
HIGHCVSS 7.1

CVE-2026-32976

CVE-2026-32976 updated by NVD

Modified
2026-07-27
Sources
nvd

Summary

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels. .accounts. to modify configuration on target accounts with configWrites: false.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.