Junglewise Threat Intelligence

CVE-2026-32027: OpenClaw DM pairing-store identities bypass group allowlist authorization

CVE-2026-32027 · Severity: low · CVSS 3.1 · Published 2026-03-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular library used for secure messaging and identity management. A flaw in how it evaluates sender permissions for group messages allows someone approved for direct messages to bypass restrictions on group communications, potentially enabling unauthorized access to group conversations they should not be able to reach.

Technical details

The vulnerability is an improper authorization check (CWE-285, CWE-863) in OpenClaw's group allowlist evaluation. When checking whether a sender is authorized to send to a group, the code incorrectly inherits identities from the DM pairing store, allowing a sender validated through direct message pairing to satisfy group allowlist checks without explicit presence in groupAllowFrom. This is a cross-context authorization boundary violation between DM and group message paths. No special authentication or network preconditions are described; the attack exploits logical flaws in policy evaluation. Versions through 2026.2.25 are affected; patched versions 2026.2.26 and later are available.

Affected products

  • OpenClaw openclaw through 2026.2.25

Timeline

  • 2026-03-03: disclosed: Advisory published (GHSA-jv6r-27ww-4gw4)
  • 2026-02-26: patched: Initial fix landed before advisory filing
  • 2026-03-19: advisory: CVE-2026-32027 assigned by NVD

References

Related threats