Loading market data...
← Back to CVE feed

CVE-2026-43579

MEDIUM CVSS 6.5 View on NVD ↗

Description

OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write permissions to persist profile configuration without requiring admin authority. Attackers with operator.write scope can modify Nostr profile settings through unprotected mutation endpoints to gain unauthorized configuration persistence.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: May 06, 2026 20:16 UTC Modified: May 06, 2026 21:20 UTC