Missing Authorization in OpenClaw - #VU132713
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass authorization for approval actions.
The vulnerability exists due to missing authorization in the QQBot native approval button callback path when handling approval button clicks. A remote user can click a visible approval button to bypass authorization for approval actions.
This affects deployments where QQBot native approval buttons are enabled and an approval message is visible to a QQ user who is not configured as an approver.