#VU126430 Improper access control in OpenClaw
Published: April 17, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to gain unauthorized access to more privileged authorization context.
The vulnerability exists due to improper access control in collect-mode queue batch dispatch when draining queued messages from different senders as one batch. A remote user can enqueue messages that are processed under the final sender's authorization context to gain unauthorized access to more privileged authorization context.
Earlier messages in a batch may inherit the trust state of the final sender.