#VU125160 Incorrect authorization in OpenClaw - CVE-2026-32924
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to bypass authorization and mention gating for reaction-derived events in group chats.
The vulnerability exists due to incorrect authorization handling in Feishu reaction event processing when handling synthetic reaction events with an omitted chat_type field. A remote attacker can send a crafted reaction-originated event to bypass authorization and mention gating for reaction-derived events in group chats.
The issue occurs because a group conversation can be misclassified as a direct message during authorization evaluation.