Incorrect authorization in OpenClaw - #VU128772
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to trigger unauthorized agent processing.
The vulnerability exists due to incorrect authorization in the Zalo plugin GROUP message dispatch path when processing Zalo GROUP messages under allowlist-style group handling. A remote attacker can send a GROUP message from a sender not present in the intended allowlist to trigger unauthorized agent processing.
Only configurations intended to restrict group traffic with allowlist-style controls are affected.