Impact
The vulnerability stems from the isApprovedElevatedSender function in the openclaw-cn project, which incorrectly handles privilege checks and allows a remote attacker to trigger the function and obtain higher level access than intended. The flaw is reflected in CWE-269, Improper Privilege Management, and in part in CWE-266 due to the underlying authentication flow that is misapplied.
Affected Systems
The issue affects the openclaw-cn product from mf-yang in all versions up to and including 0.2.1. Systems running any release in that range remain at risk until a vendor‑released fix addresses the incorrect privilege handling in the isApprovedElevatedSender function.
Risk and Exploitability
The CVSS score of 5.3 signals a moderate severity, but the publicly disclosed exploit and the ability to initiate the attack remotely heighten concern. EPSS information is not available, and the vulnerability is not currently listed in CISA KEV, yet the lack of an official patch means that a potential adversary could still roll out a successful compromise by leveraging the improper privilege escalation path.
OpenCVE Enrichment