PT-2026-26387 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-32005
CVSS v3.1
6.8
Medium
| AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block action, view submission, and view closed in shared workspace deployments. Unauthorized workspace members can bypass allowFrom restrictions and channel user allowlists to enqueue system-event text into active sessions.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw