Improper Authorization in OpenClaw - CVE-2026-33576

 

Improper Authorization in OpenClaw - CVE-2026-33576

Published: April 8, 2026


Vulnerability identifier: #VU125220
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33576
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause unauthorized network fetches and disk writes.

The vulnerability exists due to improper authorization in extensions/zalo/src/monitor.ts when processing inbound media messages before DM or pairing authorization checks. A remote attacker can send a message with media content to cause unauthorized network fetches and disk writes.

The message itself may still be rejected after the media is fetched and stored.


Affected software

OpenClaw

How to mitigate CVE-2026-33576

Install security update from vendor's website.

OpenClaw - update to 2026.3.28

External References

Related Security Bulletins