Authentication Bypass by Spoofing in OpenClaw - #VU132734
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authentication bypass by spoofing in the Zalo allowFrom feature when matching policy entries against mutable display metadata. A remote user can use mutable display metadata to match another Zalo identity's policy entry to disclose sensitive information.
Only configurations with the affected feature enabled and reachable are vulnerable.