#VU125074 Incorrect authorization in OpenClaw - CVE-2026-32027
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass group allowlist authorization.
The vulnerability exists due to incorrect authorization in group allowlist authorization checks when evaluating group message paths. A remote user can use an identity approved via DM pairing to bypass group allowlist authorization.
This is an authorization-policy boundary issue between DM pairing and group allowlists.