PT-2026-26004 · Unknown+1 · Bluebubbles+1

·

CVE-2026-22170

·

Publicado

2026-02-21

·

Atualizado

2026-03-19

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description OpenClaw, when used with the optional BlueBubbles plugin, has an access control issue. An empty 'allowFrom' configuration can cause the dmPolicy pairing and allowlist restrictions to be ineffective. This allows remote attackers to send direct messages to BlueBubbles accounts by bypassing the intended sender authorization checks. The issue stems from a misconfigured allowlist validation logic. The vulnerability affects deployments where the identifier is publicly reachable or agent tool permissions are broad, but poses a lower risk in personal setups with single-owner BlueBubbles identities. The isAllowedBlueBubblesSender() function, which delegates to isAllowedParsedChatSender(), previously returned true for empty allowlists, leading to the bypass.
Recommendations Update OpenClaw to version 2026.2.22 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05044
CVE-2026-22170
GHSA-JWF4-8WF4-JF2M

Produtos afetados

Bluebubbles
Openclaw