PT-2026-33870 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-31

·

Updated

2026-04-21

·

CVE-2026-41303

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.28
Description An authorization bypass exists in Discord text approval commands, specifically affecting the '/approve' command. This issue allows users who are permitted to send commands but are not included in the channels.discord.execApprovals.approvers allowlist to resolve pending host execution requests. The flaw is located within the extensions/discord/src/exec-approvals.ts and src/auto-reply/reply/commands-approve.ts components.
Recommendations Update to version 2026.3.28.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41303
GHSA-98HH-7GHG-X6RQ

Affected Products

Openclaw