Junglewise Threat Intelligence

CVE-2026-31998: OpenClaw Synology Chat authorization bypass in dmPolicy allowlist

CVE-2026-31998 · Severity: medium · CVSS 4 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw's Synology Chat plugin is an optional integration component that manages direct message routing and access control in OpenClaw. When configured with an allowlist-based authorization policy but left with an empty allowedUserIds list, the plugin incorrectly grants unauthorized access to all Synology senders, allowing them to trigger downstream agent and tool actions that should have been blocked.

Technical details

A policy mismatch in the Synology Chat plugin causes an authorization fail-open condition: when dmPolicy is set to "allowlist" mode but allowedUserIds is empty or unset, the webhook authentication logic incorrectly treats the empty list as an allow-all condition rather than denying access. The root cause is a mismatch between the default policy resolution and the webhook authorization logic, where empty allowedUserIds defaults to permissive behavior instead of restrictive. This affects OpenClaw versions 2026.2.22 and 2026.2.23. An attacker with Synology Chat sender access can bypass the intended access controls and dispatch unauthorized commands to downstream agents and tools. The vulnerability requires channel/plugin configuration but no additional authentication. A fix is available in version 2026.2.24 and later.

Affected products

  • OpenClaw openclaw >= 2026.2.22, <= 2026.2.23

Timeline

  • 2026-03-03: disclosed: GHSA-gw85-xp4q-5gp9 published on OSV and GitHub
  • 2026-02-25: patched: openclaw@2026.2.24 released on npm with fix commits
  • 2026-02-25: other: Advisory updated to mark >= 2026.2.24 as patched

References

Related threats