Medium severity6.1NVD Advisory· Published Mar 29, 2026· Updated Mar 31, 2026
CVE-2026-32919
CVE-2026-32919
Description
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-only session reset logic. Attackers with operator.write scope can issue agent requests containing /new or /reset slash commands to reset targeted conversation state without holding operator.admin privileges.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-jf6w-m8jw-jfxcnvdVendor Advisory
- www.vulncheck.com/advisories/openclaw-unauthorized-session-reset-via-agent-slash-commandsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.