Improper access control in OpenClaw - #VU132730
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass channel policy checks.
The vulnerability exists due to improper access control in Mattermost handlers when processing a Mattermost event with missing channel type metadata. A remote user can send a specially crafted event to bypass channel policy checks.
Only instances with the affected feature enabled and reachable are vulnerable.