Improper access control in OpenClaw - #VU135910
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization checks and perform unauthorized actions.
The vulnerability exists due to improper access control in the browser act route when handling current-tab URL checks. A remote user can invoke the affected route through a lower-trust caller or configured input path to bypass authorization checks and perform unauthorized actions.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.