#VU125187 Improper Authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass DM access control.
The vulnerability exists due to improper authorization in Synology Chat webhook route ownership handling when processing multi-account configurations with shared webhook paths. A remote user can configure or trigger a duplicate webhook path to bypass DM access control.
The issue occurs when multiple account configurations collapse onto a shared webhook path, causing route ownership replacement and loss of per-account policy separation.