Improper access control in OpenClaw - #VU126437
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass SSRF policy enforcement.
The vulnerability exists due to improper access control in existing-session browser interaction and navigation routes when handling existing-session browser interactions. A remote user can use existing-session browser routes to continue interacting with or navigating targets to bypass SSRF policy enforcement.