Incorrect authorization in OpenClaw - #VU125208

 

Incorrect authorization in OpenClaw - #VU125208

Published: April 8, 2026


Vulnerability identifier: #VU125208
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify session state.

The vulnerability exists due to incorrect authorization in Telegram direct message inline button callback handling when processing callback queries from direct messages. A remote user can send a crafted callback query to modify session state.

The issue occurs because normal direct message pairing requirements are not enforced for these callbacks.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.


External References

Related Security Bulletins