#VU125149 Authorization bypass through user-controlled key in OpenClaw - CVE-2026-32976
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to modify protected sibling-account configuration.
The vulnerability exists due to authorization bypass through user-controlled key in channel command config mutation handling when processing channel-initiated configuration mutation commands. A remote user can send crafted channel commands targeting another account scope to modify protected sibling-account configuration.
This issue is limited to account-scoped policy bypass within a single gateway deployment.