Missing Authorization in OpenClaw - #VU132694
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the message read action when handling message read requests with the affected feature enabled and reachable. A remote user can request messages from a channel without the normal channel allowlist check to disclose sensitive information.
Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.