Incorrect authorization in OpenClaw - #VU149036
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to broaden durable read or write access.
The vulnerability exists due to incorrect authorization in file-transfer allow-always approvals when reusing a standing grant for a sibling path or a different node with the same display name. A remote user can reuse an approved standing grant to broaden durable read or write access.
User interaction is required for an operator to approve the original file-transfer request.