Executive brief
OpenClaw, a tool used for managing messaging gateways, contains a security flaw in how it validates WhatsApp group identities. An attacker with low-level access can trick the system into granting them higher-level permissions by using a specific group ID to bypass security filters. This could allow unauthorized users to perform sensitive actions or access restricted data, potentially compromising the integrity of the messaging platform.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's sender validation logic. The root cause is that WhatsApp group IDs can satisfy allowlists intended for elevated or high-trust senders. A remote attacker with low-privileged access can exploit this by providing a group ID that bypasses the intended authorization checks. This allows the attacker to execute actions or access features that should be restricted to trusted operators. The vulnerability is patched in version 2026.6.6; users are advised to upgrade or restrict the affected features to trusted operators only.
Affected products
- OpenClaw OpenClaw >= 2026.3.22, < 2026.6.6
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-13: disclosed: NVD publication date