Improper access control in OpenClaw - CVE-2026-41348
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass a channel restriction.
The vulnerability exists due to improper access control in the native Discord slash and autocomplete paths when handling slash commands in group DM channels. A remote user can invoke slash commands through those paths to bypass a channel restriction.
The impact is limited to already-authorized Discord users and does not cross a stronger trust boundary.