Missing Authorization in OpenClaw - CVE-2026-27158
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass JID authorization restrictions for reaction targeting.
The vulnerability exists due to missing authorization in the WhatsApp reaction action when handling reaction requests with a forged chatJid and a valid messageId. A remote user can submit a crafted reaction request to bypass JID authorization restrictions for reaction targeting.
The issue is limited to reaction actions in allowFrom-restricted WhatsApp workflows.