Incorrect authorization in OpenClaw - #VU132714
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass authorization controls and execute administrative commands.
The vulnerability exists due to incorrect authorization in the chat.send route handling when delivering a scoped Gateway request into a session with an inherited external delivery route. A remote user can send a crafted chat.send request to bypass authorization controls and execute administrative commands.
This affects scoped Gateway clients and does not apply to shared-secret bearer HTTP compatibility endpoints.