Executive brief
OpenClaw's BlueBubbles group messaging feature has an authorization flaw where users who are only paired for direct messages (DM) can incorrectly be treated as authorized for group messages when certain policy configurations are active. This could allow unauthorized users to send messages and reactions to restricted groups without being explicitly added to the group's allow list. The issue is constrained to specific deployment configurations and does not bypass broader security boundaries.
Technical details
This is an authorization logic flaw (CWE-863) in OpenClaw's DM/group allowlist composition mechanism. The root cause is that DM pairing-store identities could flow into group authorization decisions, allowing DM-paired senders to be treated as group-authorized. The vulnerability affects deployments where groupPolicy=allowlist and dmPolicy=pairing are simultaneously enabled and pairing-store entries exist. An attacker with only DM pairing authorization could craft or relay messages and reactions that would pass group-level sender checks without explicit membership in groupAllowFrom. The fix centralizes DM/group authorization composition via shared resolvers to prevent pairing-store leakage into group auth logic. The patch is available in version 2026.2.26.
Affected products
- OpenClaw openclaw <= 2026.2.25
Timeline
- 2026-03-03: disclosed: Advisory published by GitHub
- 2026-02-26: patched: Fix commit 051fdcc428129446e7c084260f837b7284279ce9
- 2026-03-19: other: NVD published entry for CVE-2026-32006
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-25pw-4h6w-qwvm
- https://github.com/openclaw/openclaw/commit/051fdcc428129446e7c084260f837b7284279ce9
- https://github.com/openclaw/openclaw/commit/1aadf26f9acc399affabd859937a09468a9c5cb4
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-dm-pairing-store-fallback-in-group-allowlist