PT-2026-26748 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-03

·

Updated

2026-03-21

·

CVE-2026-32899

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.25
Description The software does not consistently enforce sender-policy checks on reaction * and pin * non-message events before incorporating them into the system-event context. This allows attackers to circumvent established Direct Message policies and user allowlists, enabling the injection of unauthorized reaction and pin events originating from restricted senders.
Recommendations Update OpenClaw to version 2026.2.25 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32899
GHSA-G839-VP47-WGH8
GHSA-RM2P-J3R7-4X4J

Affected Products

Openclaw