Improper access control in OpenClaw - #VU126434
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass approval authorization checks.
The vulnerability exists due to improper access control in helper-backed channel approval resolution when processing an empty resolved approver list. A remote user can resolve pending approvals using a known approval id to bypass approval authorization checks.
The issue affects senders outside the normal channel authorization gate.