Missing Authorization in OpenClaw - #VU132773
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to bypass owner-only tool policy and invoke owner-only behavior.
The vulnerability exists due to missing authorization in the MCP loopback path when the affected feature is enabled and reachable. A local user can reach the affected loopback path as a non-owner caller to bypass owner-only tool policy and invoke owner-only behavior.
Practical impact depends on the operator's configuration and whether lower-trust input can reach that path.