Improper access control in OpenClaw - #VU126434
Published: April 17, 2026
Vulnerability details
The vulnerability allows a remote user to bypass approval authorization checks.
The vulnerability exists due to improper access control in helper-backed channel approval resolution when processing an empty resolved approver list. A remote user can resolve pending approvals using a known approval id to bypass approval authorization checks.
The issue affects senders outside the normal channel authorization gate.