Openclaw cli: OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope (CVE-2026-35619)
Description
OpenClaw CLI versions from 2026.1.29 up to but not including 2026.3.24 contain an authorization bypass vulnerability on the HTTP /v1/models endpoint. This endpoint accepts bearer tokens but does not enforce the required operator.read scope, unlike the WebSocket RPC path which correctly enforces scope checks. As a result, operators with only operator.approvals scope can enumerate model metadata via HTTP, bypassing intended access controls. This inconsistency weakens least-privilege enforcement for operators. The issue is fixed in OpenClaw 2026.3.24.
CVSS v3.1
Score 4.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenClaw CLI has a cross-surface authorization inconsistency (CVE-2026-35619) where the HTTP /v1/models route does not enforce the operator.read scope required for listing models, unlike the WebSocket RPC path which enforces this scope. Operators with only operator.approvals scope can successfully fetch model metadata via HTTP /v1/models despite being denied access over WebSocket RPC. This bypass breaks scope consistency and least-privilege expectations. The vulnerability affects versions >=2026.1.29 and <2026.3.24 and was fixed in 2026.3.24 by enforcing scope checks on HTTP endpoints and reusing centralized authorization logic.
Potential Impact
Operators lacking the operator.read scope can enumerate gateway model metadata through the HTTP /v1/models endpoint, bypassing intended access restrictions. This breaks the consistency of scope enforcement between WebSocket and HTTP interfaces, weakening the security model and potentially exposing sensitive model metadata to unauthorized operators. There is no indication of impact beyond information disclosure of model metadata. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix is available in OpenClaw version 2026.3.24. Operators should upgrade to this version or later to ensure that the HTTP /v1/models endpoint enforces the operator.read scope consistently with the WebSocket RPC path. The patch applies centralized scope authorization logic to HTTP routes to prevent this bypass. No additional mitigation actions are required beyond applying the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-35619
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac245b012601ec6a3166b18
Added to database: 10/04/2026, 12:25:20 UTC
Last enriched: 10/04/2026, 12:56:48 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.