Junglewise Threat Intelligence

CVE-2026-41367: OpenClaw authorization bypass in Discord component interactions

CVE-2026-41367 · Severity: medium · CVSS 5 · Published 2026-04-28

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing Discord bot interactions, contains a security flaw where it fails to properly check permissions for button and component clicks. This allows users to perform restricted actions or bypass channel-specific rules that should normally block them. An attacker could use this to trigger administrative or privileged functions in Discord channels where they are supposed to be restricted.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's Discord extension, specifically within the component interaction ingress logic. The software fails to reapply guild and channel policy gates to button and component interactions, even though these gates are correctly applied to standard inbound messages. A remote attacker with low privileges can exploit this by interacting with Discord UI components from contexts (channels or guilds) that should be blocked by policy. This allows the execution of privileged component actions that would otherwise be restricted. The issue is fixed in version 2026.3.28.

Affected products

  • OpenClaw OpenClaw 2026.2.14 through 2026.3.24

Timeline

  • 2026-03-29: advisory: GitHub Security Advisory published
  • 2026-04-27: disclosed: NVD and VulnCheck disclosure
  • 2026-03-28: patched: Version 2026.3.28 released with fix

References

Related threats