PT-2026-27238 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32904

CVSS v3.1

4.6

Medium

AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
OpenClaw before 2026.2.26 contains an authorization bypass vulnerability in group allowlist policy evaluation that accepts sender identities from DM pairing-store approvals. Attackers can exploit this boundary weakness by obtaining DM pairing approval to bypass group allowlist checks and gain unauthorized group access.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32904

Affected Products

Openclaw