Incorrect authorization in OpenClaw - #VU135902
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to improper access control in hooks allowedAgentIds handling when processing blank agent IDs. A remote user can supply a blank agent ID to bypass authorization checks.
Only the named feature and configuration are affected, and practical impact depends on whether lower-trust input can reach the vulnerable path.