Improper access control in OpenClaw - #VU132726
Published: May 29, 2026
Vulnerability details
The vulnerability allows a remote user to bypass hook-based auditing or policy checks.
The vulnerability exists due to improper access control in the skill-command dispatch path when processing skill commands through the affected feature. A remote user can invoke a skill command through that path to bypass hook-based auditing or policy checks.
Only instances where the affected feature is enabled and reachable are vulnerable.