Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-100578 Multiple Vendors

Vulnerabilidad alta en OpenClaw (npm) permite escalación de privilegios en Gateway

Vulnerabilidad · Publicado 26/09/2026

7.6
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

OpenClaw versiones anteriores a 2026.7.1 expone herramientas administrativas restringidas (gateway y cron) a través del endpoint chat.send, permitiendo que usuarios sin permisos de propietario ejecuten operaciones privilegiadas en despliegues con autenticación. Afecta principalmente a infraestructuras en nube que utilizan este paquete npm en sistemas de orquestación y automatización.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool inventory includes the `gateway` and `cron` tools, causing the agent to invoke owner-only configuration or scheduling operations, including persistent state changes. Practical impact depends on the tools selected by the model and the caller's ability to steer the turn. Shared-secret token and password callers are treated as fully trusted operators under OpenClaw's security model and are outside the scope of this issue. The issue is fixed in 2026.7.1; as a workaround, restrict chat.send to administrators in identity-bearing deployments and remove `gateway` and `cron` from affected agent tool policies.

Puntuación CVSS

Score: 7.6/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Debilidades (CWE)

CWE-269

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Actualizar OpenClaw a versión 2026.7.1 o posterior inmediatamente
  • Auditar logs de chat.send para detectar invocaciones anómalas de herramientas gateway/cron
  • Implementar validación adicional de permisos de propietario en endpoints expuestos
  • Monitorear despliegues Gateway en producción y aplicar restricciones de scope de operador más estrictas
Esta alerta fue generada automáticamente a partir del NVD del NIST.