#VU125115 Incorrect authorization in OpenClaw - CVE-2026-32035
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to access owner-only tool surfaces.
The vulnerability exists due to incorrect authorization in the Discord voice transcript path and agentCommand(...) when processing voice transcript turns without senderIsOwner. A remote user can participate in the same Discord voice channel and trigger transcript-driven commands to access owner-only tool surfaces.
Exploitation requires Discord voice to be enabled and the bot to be present in a channel with non-owner participants. User interaction is required.