#VU125153 Reliance on Untrusted Inputs in a Security Decision in OpenClaw - CVE-2026-32975
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to bypass channel authorization.
The vulnerability exists due to reliance on untrusted inputs in a security decision in Zalouser allowlist authorization when matching group identifiers for group routing. A remote attacker can reuse the display name of an allowlisted group to bypass channel authorization.
This issue occurs in deployments that use name-based channels.zalouser.groups entries together with permissive sender allowlists.