Improper access control in OpenClaw - #VU132771
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to execute owner-style commands across channel boundaries.
The vulnerability exists due to improper access control in internal/webchat command authorization when handling sender input on an affected internal or webchat path. A remote user can send input through the affected path to execute owner-style commands across channel boundaries.
Only configurations with the affected feature enabled and reachable are vulnerable.