Improper access control in OpenClaw - #VU132695
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass command allowlist restrictions.
The vulnerability exists due to improper access control in the shell wrapper command approval and execution logic when processing a command request using a shell wrapper form. A remote user can submit a crafted command request to bypass command allowlist restrictions.
Only instances with the affected feature enabled and reachable are vulnerable.