#VU125081 Incorrect authorization in OpenClaw - CVE-2026-32895
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information and modify system event processing.
The vulnerability exists due to incorrect authorization in Slack system event handlers in src/slack/monitor/events/members.ts and src/slack/monitor/events/messages.ts when handling member_* and message subtype system events. A remote user can send unauthorized system events from a non-allowlisted sender to disclose sensitive information and modify system event processing.
Deployments relying on Slack DM allowlists or per-channel user allowlists are affected.