Incorrect authorization in OpenClaw - #VU132714
Published: May 29, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization controls and execute administrative commands.
The vulnerability exists due to incorrect authorization in the chat.send route handling when delivering a scoped Gateway request into a session with an inherited external delivery route. A remote user can send a crafted chat.send request to bypass authorization controls and execute administrative commands.
This affects scoped Gateway clients and does not apply to shared-secret bearer HTTP compatibility endpoints.