Incorrect authorization in OpenClaw - #VU129407
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform broader-than-intended owner-only gateway actions.
The vulnerability exists due to incorrect authorization in gateway tool access checks when handling specific authenticated non-owner DM tool invocation flows. A remote user can invoke a specific tool path to perform broader-than-intended owner-only gateway actions.
This issue is limited to authenticated non-owner sender sessions in direct messages and does not provide direct code execution by itself.