Executive brief
OpenClaw, a tool used for managing Discord integrations, contains a security flaw in how it handles Discord server (guild) actions. This vulnerability allows users with low-level access to bypass security checks and perform restricted administrative tasks they should not be authorized to do. If exploited, an attacker could disrupt server operations or modify settings, potentially leading to unauthorized changes or service outages.
Technical details
An authorization bypass vulnerability exists in OpenClaw's Discord guild actions due to incorrect authorization (CWE-863). The flaw stems from misconfigured input paths that allow a requester to skip cross-provider authorization checks. A network-based attacker with low-level privileges can exploit this to execute restricted operations that should require higher trust levels or stricter policy enforcement. The vulnerability specifically impacts integrity and availability but does not appear to expose confidential data. A fix is available in version 2026.6.9.
Affected products
- OpenClaw OpenClaw 2026.6.6 to 2026.6.8
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-13: disclosed: NVD publication date