Incorrect authorization in OpenClaw - CVE-2026-32899
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to introduce unauthorized reaction or pin context signals.
The vulnerability exists due to incorrect authorization in Slack non-message event handlers when processing reaction_* and pin_* events before applying sender-policy checks consistently. A remote attacker can send unauthorized non-message events to introduce unauthorized reaction or pin context signals.
The issue affects system-event context for non-message Slack ingress.