PT-2026-26387 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-32005

CVSS v3.1

6.8

Medium

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block action, view submission, and view closed in shared workspace deployments. Unauthorized workspace members can bypass allowFrom restrictions and channel user allowlists to enqueue system-event text into active sessions.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32005

Affected Products

Openclaw