Improper Authentication in OpenClaw - #VU128826
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper authentication in Discord allowlist name/tag matching when processing slug-normalized Discord names and tags. A remote attacker can use a colliding user tag to bypass authorization checks.
Name-based allowlist entries can unintentionally match different Discord users after slug normalization.