Improper access control in OpenClaw - #VU128844
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to access canvas routes beyond intended authorization boundaries.
The vulnerability exists due to improper access control in canvas routes when handling network-visible canvas access requests in mixed-trust deployments. A remote attacker can send requests without an explicit token or session capability to access canvas routes beyond intended authorization boundaries.
Risk is highest in non-loopback or mixed-trust environments.