Vulnerability  ·  2026-09-30

OpenClaw mcp.app.view authorization bypass lets read-scoped operators invoke write-scoped MCP tools

VulnerabilityMedium impactGlobalCVE-2026-102807
NVD published CVE-2026-102807 (CVSS 5.3 v3.1 / 6.0 v4.0) on 2026-09-29. OpenClaw's mcp.app.view method (incorrect authorization, CWE-863) lets read-scoped operators escalate to write-scope tool execution via a redeemable standalone ticket, fixed in OpenClaw 2026.9.4.
OpenClaw is a personal AI-agent gateway (handling messaging, home automation, and tool access). The read-to-write scope confusion means a read-authorized operator can trigger state-changing, potentially destructive MCP app actions — an agent authorization boundary failure in the identity-scoping model defenders rely on to contain agent actions.
An attacker holding operator.read-scope tokens calls mcp.app.view to obtain a standalone ticket, then redeems it at the MCP App view endpoint to execute MCP tooling that requires operator.write scope — state-changing actions without the intended authorization checks.
OpenClaw (npm openclaw) before 2026.9.4
Upgrade to OpenClaw 2026.9.4+ (fix commit 3bd8ec2, PR #142661; releases doc https://docs.openclaw.ai/releases/2026.9.4).
NVD CVE-2026-102807OpenClaw 2026.9.4 release notesVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →