#VU125208 Incorrect authorization in OpenClaw

 

#VU125208 Incorrect authorization in OpenClaw

Published: April 8, 2026


Vulnerability identifier: #VU125208
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OpenClaw
Software vendor:
OpenClaw

Description

The vulnerability allows a remote user to modify session state.

The vulnerability exists due to incorrect authorization in Telegram direct message inline button callback handling when processing callback queries from direct messages. A remote user can send a crafted callback query to modify session state.

The issue occurs because normal direct message pairing requirements are not enforced for these callbacks.


Remediation

Install security update from vendor's website.

External links