Impact
OpenClaw's diagnostics-prometheus plugin up to 2026.9.2 omitted the operator.read scope check on its metrics endpoint. As a result, a caller with any authenticated identity that does not possess read scope can still retrieve operational metrics when Gateway authentication mode such as trusted-proxy is used. This leads to unauthorized disclosure of metrics to authenticated users whose permissions are intended to be limited, violating confidentiality.
Affected Systems
The vulnerability affects installations of the OpenClaw diagnostics-prometheus service with a version earlier than 2026.9.3. This includes setups that use Gateway-based authentication, such as trusted-proxy, where the identity payload is forwarded to the diagnostics-prometheus endpoint.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate overall risk. Because the attack requires an authenticated identity via Gateway, an attacker who can obtain such credentials but lacks read scope can read the metrics. EPSS score is not published, and the vulnerability is not currently listed in the CISA KEV catalog. No remote code execution or privilege escalation is possible; the flaw is limited to information disclosure. Nevertheless, the unintended data leakage warrants immediate correction.
OpenCVE Enrichment