#VU125072 Incorrect authorization in OpenClaw - CVE-2026-32006
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass group authorization checks.
The vulnerability exists due to incorrect authorization in BlueBubbles group authorization handling when processing message and reaction ingress with dmPolicy=pairing and groupPolicy=allowlist. A remote user can send messages or reactions from a DM-paired identity that is not explicitly present in groupAllowFrom to bypass group authorization checks.
Only deployments using BlueBubbles with groupPolicy=allowlist and dmPolicy=pairing are affected, and pairing-store entries must be present.