Improper access control in OpenClaw - #VU126838
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to bypass configured tool policy restrictions.
The vulnerability exists due to improper access control in bundled MCP/LSP tool handling when merging bundled tools into the agent's effective tool set after policy filtering. A local user can use a bundled MCP or LSP tool source that should have been restricted by policy to bypass configured tool policy restrictions.
Exploitation requires a configured bundled MCP or LSP tool source and an operator policy that would otherwise restrict that tool.