Improper access control in OpenClaw - #VU126833
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass webhook routing isolation.
The vulnerability exists due to improper access control in hook mapping sessionKey handling when rendering templated hook mapping session keys. A remote attacker can influence a template-rendered session key to bypass webhook routing isolation.
This issue does not grant host execution by itself.