Incorrect authorization in OpenClaw - CVE-2026-31998
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to trigger downstream agent or tool actions.
The vulnerability exists due to incorrect authorization in the synology-chat channel plugin webhook authorization logic when handling inbound Synology direct messages with dmPolicy set to allowlist and allowedUserIds empty or unset. A remote user can send messages through Synology Chat to trigger downstream agent or tool actions.
Exploitation requires the optional synology-chat channel plugin to be configured.