PT-2026-49780 · Openclaw · Openclaw
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.25
Description
An input validation issue exists in tool group policy callers that accept unvalidated group IDs. An attacker capable of supplying a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, which may lead to the bypass of intended access controls. The practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Recommendations
Update to version 2026.4.25.
Avoid exposing group-policy controlled tools to untrusted senders.
Keep channel and tool allowlists narrow.
Avoid sharing one Gateway between mutually untrusted users.
Disable the affected feature when it is not needed.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw