Junglewise Threat Intelligence

CVE-2026-32924: OpenClaw Feishu reaction events authorization bypass

CVE-2026-32924 · Severity: medium · CVSS 4 · Published 2026-03-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a library that handles messaging integration with Feishu (a workplace collaboration platform). A bug in reaction-event processing allows attackers to bypass group authorization and mention-gating protections by misclassifying group conversations as direct messages. This could allow unauthorized users to trigger actions or view content that should be restricted to group members or specific mentions.

Technical details

The vulnerability is an authorization bypass (CWE-285, CWE-863) affecting Feishu reaction-originated synthetic events. When processing a reaction payload that omits the chat_type field, OpenClaw incorrectly classifies the conversation as peer-to-peer (p2p) rather than group. Authorization and mention-gating logic relies on this chat_type classification; using the wrong type causes group-message authorization checks to be skipped, and the event is evaluated as a direct message instead. Attack requires control over or manipulation of inbound Feishu reaction payloads. The fix, released in version 2026.3.12, preserves the correct chat_type from the fetched message context and fails safely when insufficient chat context is available.

Affected products

  • OpenClaw openclaw <= 2026.3.11

Timeline

  • 2026-03-13: disclosed
  • 2026-03-12: patched: Fix released in version 2026.3.12

References

Related threats