#VU125289 Improper access control in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to modify allowlists for a different channel.
The vulnerability exists due to improper access control in the /allowlist endpoint when handling cross-channel allowlist write requests. A remote user can send a crafted allowlist write request to modify allowlists for a different channel.
This issue is scoped to the product's local assistant trust model and does not assume a multi-tenant service boundary.