PT-2026-49766 · Openclaw · Openclaw
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.7
Description
The
allowFrom feature improperly validates Discord account identity by using mutable display names instead of immutable user IDs. This allows an attacker to change their display or global name metadata to match a policy entry, potentially gaining unauthorized agent access intended for a different Discord identity. This issue is specific to the named feature and configuration and does not affect the trusted-operator model regarding authenticated Gateway operators, installed plugins, or local execution surfaces.Recommendations
Update to version 2026.5.7.
Use stable Discord user IDs in allowlists.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the
allowFrom feature when it is not needed.Exploit
Fix
LPE
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw