{"id":"CVE-2026-32976","aliases":["GHSA-8jhh-jcqg-mj5p"],"url":"https://o3.security/vulnerability/CVE-2026-32976","summary":"OpenClaw < 2026.3.11 - Account-Scoped configWrites Policy Bypass via Channel Commands","details":"OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false.","published":"2026-03-31T11:17:17.986Z","modified":"2026-08-17T03:48:14.349119810Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.3.11"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32976.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-8jhh-jcqg-mj5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32976"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-account-scoped-configwrites-policy-bypass-via-channel-commands"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T03:48:14.349119810Z"}}