Junglewise Threat Intelligence

CVE-2026-44991: OpenClaw authorization bypass in owner-enforced commands

CVE-2026-44991 · Severity: medium · CVSS 4.2 · Published 2026-05-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a communication and automation platform, contains a flaw where unauthorized users can execute administrative commands. If a channel is configured to allow messages from anyone but lacks specific owner restrictions, the system mistakenly grants administrative 'owner' privileges to any sender. This allows unauthorized individuals to change configurations, send messages as the bot, or access debugging tools.

Technical details

A missing authorization vulnerability exists in OpenClaw's 'command-auth.ts' component. When a channel plugin has 'enforceOwnerForCommands' enabled and uses a wildcard 'allowFrom' policy without an explicit 'ownerAllowFrom' setting, the system incorrectly reuses the wildcard sender policy for command authorization. This allows any network-reachable sender to bypass the owner-only gate for sensitive slash commands like /send, /config, and /debug. The issue is resolved in version 2026.4.21 by requiring concrete owner identities or internal admin scopes.

Affected products

  • OpenClaw openclaw <= 2026.4.20

Timeline

  • 2026-04-22: patched: Initial patch release 2026.4.21
  • 2026-04-29: advisory: GitHub Advisory published

References

Related threats