CVE-2026-34512 | OpenClaw up to 2026.3.24 kill killSubagentRunAdmin authorization (GHSA-9p93-7j67-5pc2 / WID-SEC-2026-0884)
A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.3.24. Affected by this vulnerability is the function killSubagentRunAdmin of the file /sessions/:sessionKey/kill. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-34512. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.