---
id: CVE-2026-35674
title: OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
summary: >-
  OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway
  chat.send route that allows scoped clients to execute privileged commands.
  Attackers with operator.write scope can deliver commands through inherited
  external…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-863
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.5.18
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-29T19:32:26.331094Z'
published: '2026-05-29'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:34.070Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-35674'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-hw9r-h9mr-4jff
    label: GitHub Security Advisory (GHSA-hw9r-h9mr-4jff)
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-scope-bypass-via-inherited-chat-send-route
tags:
  - cve.org
epss: 0.00451
epssPercentile: 0.36464
ingestedAt: '2026-09-24T15:45:56.732Z'
---

## Overview

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope requirements, enabling unauthorized plugin, config, MCP, allowlist, and ACP mutations.

## Affected

- `OpenClaw < 2026.5.18`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
