Executive brief
OpenClaw, a tool for managing gateway operations and plugins, contains a vulnerability where it fails to properly validate group identifiers. This could allow an authorized user to bypass intended security policies and execute tools or actions they should not have access to. An exploit could lead to unauthorized system modifications or the bypass of organizational access controls.
Technical details
A vulnerability classified as CWE-639 (Authorization Bypass Through User-Controlled Key) exists in OpenClaw's tool group policy resolver. The component fails to validate group IDs supplied by callers, allowing a user with low privileges to resolve policies for unvalidated groups. This can result in the application of incorrect group-policy decisions during tool invocation. The attack is reachable over the network but requires the 'affected feature' to be enabled and the attacker to have at least low-level authenticated access. The issue is addressed in version 2026.4.25.
Affected products
- openclaw openclaw <= 2026.4.24
Timeline
- 2026-05-28: disclosed
- 2026-06-18: advisory
- 2026-04-25: patched