PT-2026-35555 · Openclaw · Openclaw
Keensecuritylab
+2
·
Published
2026-04-27
·
Updated
2026-04-28
·
CVE-2026-41367
CVSS v3.1
5.0
Medium
| AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N |
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw