Improper access control in OpenClaw - #VU132769
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to modify focus state outside the intended authority.
The vulnerability exists due to improper access control in the focus command when the affected feature is enabled and reachable. A remote user can trigger the focus command to modify focus state outside the intended authority.
Only configurations where lower-trust input can reach the affected path are exposed.