PT-2026-26409 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-32028
CVSS v3.1
3.7
Low
| AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-message reaction notifications, allowing non-allowlisted users to enqueue reaction-derived system events. Attackers can exploit this inconsistency by reacting to bot-authored DM messages to bypass DM authorization restrictions and trigger downstream automation or tool policies.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw