CVE-2026-43579
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write permissions to persist profile configuration without requiring admin authority. Attackers with operator.write scope can modify Nostr profile settings through unprotected mutation endpoints to gain unauthorized configuration persistence.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/security/advisories/GHSA-f3h5-h452-vp3j
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/6517c700de9bb0ee11b41ab625ef3b63d01b6083
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openclaw | openclaw | {"endExcluding":"2026.4.10"} | 2026.4.10 |
References
CWEs
CWE-862
Verify integrity in audit chain (admin only). AS-IS.