Authorization bypass through user-controlled key in OpenClaw - CVE-2026-32021
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to authorization bypass through a user-controlled key in Feishu allowlist authorization checks when matching sender identities against the allowlist. A remote attacker can set a display name equal to an allowlisted ID string to bypass authorization checks.
Only deployments using Feishu allowlist-based authorization are affected.