#VU125076 Incorrect authorization in OpenClaw - CVE-2026-31991
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass group allowlist authorization.
The vulnerability exists due to incorrect authorization in shared DM/group policy resolution when evaluating Signal group authorization under groupPolicy=allowlist. A remote user can use sender identities sourced from DM pairing-store approvals to bypass group allowlist authorization.
User interaction is required.