Executive brief
OpenClaw is an open-source platform used to manage group communication and access policies. A vulnerability in its sender authorization system allows attackers to escalate their permissions by exploiting how the system matches sender identities—an attacker could assume the privileges of another sender if they can create a colliding identifier, potentially gaining unauthorized access to restricted tools and capabilities.
Technical details
The vulnerability is a sender-authorization bypass in the toolsBySender policy matching logic (CWE-639, CWE-863). When deployments use untyped sender keys, the system fails to distinguish between different identity attributes (senderName, senderUsername, etc.), allowing an attacker to craft a colliding mutable identity value and inherit tool permissions intended for a different sender. The attack requires an authenticated attacker (authentication is a precondition). The fix introduces explicit typed sender keys (id, e164, username, name) and deprecates legacy untyped key matching. Patched version 2026.2.22 is planned; all versions <= 2026.2.21-2 are affected.
Affected products
- OpenClaw OpenClaw <= 2026.2.21-2
Timeline
- 2026-03-03: disclosed: Advisory published
- 2026-03-03: patched: Fix committed; patched version 2026.2.22 planned