PT-2026-37029 · Openclaw · Openclaw
Anshuman Bhartiya
·
Published
2026-04-17
·
Updated
2026-05-05
·
CVE-2026-43574
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.12
Description
An improper authorization issue exists in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. This logic flaw allows attackers to resolve pending approvals without proper authorization, provided they possess an approval id.
Recommendations
Update to version 2026.4.12 or newer.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw