#VU125208 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to modify session state.
The vulnerability exists due to incorrect authorization in Telegram direct message inline button callback handling when processing callback queries from direct messages. A remote user can send a crafted callback query to modify session state.
The issue occurs because normal direct message pairing requirements are not enforced for these callbacks.