Improper access control in OpenClaw - #VU129438
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to obtain unintended approvals for risky tool permissions.
The vulnerability exists due to improper access control in ACP permission handling when processing permission requests for non-read or non-search tools. A remote user can trigger permission requests that are auto-approved to obtain unintended approvals for risky tool permissions.
This issue affects ACP-integrated scenarios where insufficient user interaction or guardrails reduce friction for silent execution or mutation.