Improper access control in OpenClaw - #VU132728
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify sender-agent binding state beyond the intended policy.
The vulnerability exists due to improper access control in Feishu dynamic-agent bindings when handling create or update binding operations with dynamic-agent binding behavior enabled. A remote user can create or update bindings without honoring the configured config-write control to modify sender-agent binding state beyond the intended policy.
Only instances with the affected feature enabled and reachable are vulnerable.