Incorrect authorization in OpenClaw - CVE-2026-35652
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform unauthorized sender actions.
The vulnerability exists due to incorrect authorization in Mattermost interactive callback dispatch in extensions/mattermost/src/mattermost/interactions.ts and callback authorization routing in extensions/mattermost/src/mattermost/monitor.ts when handling interactive callbacks. A remote user can send a crafted callback to perform unauthorized sender actions.