CVE-2026-102807
Received Received - Intake

Incorrect Authorization in OpenClaw MCP App Tools

Vulnerability report for CVE-2026-102807, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.9.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw before version 2026.9.4 has a flaw where operators with read-only permissions can misuse the mcp.app.view method to execute MCP App tools that require write permissions. This happens because the system allows redeeming a standalone ticket to invoke state-changing tools without proper authorization checks.

Impact Analysis

Attackers with operator.read tokens could exploit this to perform unauthorized actions, such as modifying application states or accessing sensitive data, even though they only have read permissions. This could lead to data breaches or system misuse.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access or modifications to sensitive data, potentially leading to data breaches. GDPR and HIPAA require strict access controls and auditability, which this flaw undermines.

Mitigation Strategies

Update OpenClaw to version 2026.9.4 or later to address the authorization flaw. Review operator token permissions to ensure read-scoped tokens cannot invoke state-changing MCP App tools. Monitor network traffic for unauthorized MCP app view endpoint interactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102807. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart