PT-2026-26743 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-32067

CVSS v3.1

3.7

Low

AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
OpenClaw versions prior to 2026.2.26 contains an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32067

Affected Products

Openclaw