Improper access control in OpenClaw - #VU132726
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass hook-based auditing or policy checks.
The vulnerability exists due to improper access control in the skill-command dispatch path when processing skill commands through the affected feature. A remote user can invoke a skill command through that path to bypass hook-based auditing or policy checks.
Only instances where the affected feature is enabled and reachable are vulnerable.