Incorrect authorization in OpenClaw - #VU128585
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify persistent Matrix profile configuration.
The vulnerability exists due to incorrect authorization in Matrix profile persistence when invoking gateway operator.write message-tool paths. A remote user can use write-scoped message tools to modify persistent Matrix profile configuration.
The affected functionality should have required admin-level authority.