Incorrect authorization in OpenClaw - CVE-2026-26328
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform unauthorized commands in group contexts.
The vulnerability exists due to incorrect authorization in src/imessage/monitor/monitor-provider.ts when evaluating iMessage group allowlist authorization. A remote user can use a sender identity approved through the DM pairing store to perform unauthorized commands in group contexts.
Only iMessage deployments using groupPolicy=allowlist are vulnerable.