CVE-2026-34512
Received Received - Intake
Improper Access Control in OpenClaw Allows Admin Session Hijacking

Publication date: 2026-04-09

Last updated on: 2026-04-15

Assigner: VulnCheck

Description
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated user to invoke admin-level session termination functions without proper scope validation. Attackers can exploit this by sending authenticated requests to kill arbitrary subagent sessions via the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-09
Last Modified
2026-04-15
Generated
2026-05-07
AI Q&A
2026-04-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.3.25 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in OpenClaw versions before 2026.3.25 and involves improper access control in the HTTP /sessions/:sessionKey/kill route.

Any user authenticated with a bearer token can invoke admin-level session termination functions without proper scope validation.

Attackers can exploit this by sending authenticated requests to kill arbitrary subagent sessions using the killSubagentRunAdmin function, bypassing ownership and operator scope restrictions.


How can this vulnerability impact me? :

This vulnerability allows an attacker with bearer authentication to terminate arbitrary subagent sessions at an admin level without proper authorization.

Such unauthorized session termination can disrupt normal operations, potentially causing denial of service or loss of control over session management.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart