PT-2026-26004 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-18
·
Updated
2026-03-18
·
CVE-2026-22170
CVSS v3.1
4.8
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attackers can send direct messages to BlueBubbles accounts by exploiting the misconfigured allowlist validation logic to bypass intended sender authorization checks.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw