---
id: CVE-2026-102807
title: >-
  OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in
  the mcp.app.view method that allows read-scoped operators to execute MCP App
  tools requiring operator.write scope
summary: >-
  OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in
  the mcp.app.view method that allows read-scoped operators to execute MCP App
  tools requiring operator.write scope. Attackers with operator.read tokens can
  obta…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-863
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.9.4
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:13.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102807'
references:
  - url: 'https://docs.openclaw.ai/releases/2026.9.4'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openclaw/openclaw'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/blob/1391f7cd2d40ab5bbcf2f5f831d3a64f520e72d7/src/gateway/mcp-app-standalone.ts#L209-L215
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/commit/3bd8ec2b39b5f9e80aef0973f7d17eadc745b8f8
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openclaw/openclaw/pull/142661'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.9.4-authorization-bypass-via-mcp-app-standalone-ticket
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-29T17:58:34.738470Z'
ingestedAt: '2026-09-29T17:41:02.258Z'
---

## Overview

OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
