#VU125069 Incorrect authorization in OpenClaw - CVE-2026-32067
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass authorization boundaries across accounts and gain unauthorized access to direct message pairing approvals.
The vulnerability exists due to incorrect authorization in pairing-store access for DM pairing policy when handling pairing approvals in multi-account setups. A remote user can reuse a pairing approval from one account to bypass authorization boundaries across accounts and gain unauthorized access to direct message pairing approvals.
User interaction is required, and the issue affects multi-account channel deployments.