PT-2026-27243 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32911

CVSS v3.1

6.4

Medium

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
OpenClaw versions 2026.2.22 prior to 2026.2.24 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can bypass authorization checks to dispatch unauthorized messages to downstream agents and tools.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32911

Affected Products

Openclaw