Executive brief
OpenClaw, a tool used for managing bot interactions, contains a security flaw in its QQBot integration. This vulnerability allows unauthorized users to bypass access control rules and execute commands that should have been blocked. Depending on how the bot is configured, this could lead to unauthorized actions being performed within the chat environment or connected systems.
Technical details
An authorization bypass vulnerability exists in OpenClaw's QQBot implementation due to incorrect sequencing of command dispatching and policy enforcement. Specifically, slash commands are dispatched before the 'allowFrom' access control policies are applied. This allows a sender who is otherwise blocked by policy to successfully trigger command handling. The vulnerability is classified as CWE-863 (Incorrect Authorization). Attackers can exploit this over the network without user interaction to execute restricted commands. The issue is resolved in version 2026.4.27.
Affected products
- OpenClaw OpenClaw < 2026.4.27
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date