PT-2026-26732 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-32050

CVSS v3.1

3.7

Low

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized senders to enqueue status events before authorization checks are applied. Attackers can exploit the reaction-only event path in event-handler.ts to queue signal reaction status lines for sessions without proper DM or group access validation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32050

Affected Products

Openclaw