Authorization bypass through user-controlled key in OpenClaw - CVE-2026-35624
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass room authorization.
The vulnerability exists due to authorization bypass through a user-controlled key in the Nextcloud Talk room allowlist authorization logic when matching room identities by collidable room names instead of stable room tokens. A remote user can use a similarly named room to bypass room authorization.