#VU125185 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to perform unauthorized queued node actions.
The vulnerability exists due to incorrect authorization in queued node action delivery when delivering previously queued actions after command policy changes. A remote user can queue an action before policy tightening and have it delivered later to perform unauthorized queued node actions.