Executive brief
OpenClaw, an automation and gateway tool, contains a security flaw in its QQBot execution approval feature. This vulnerability allows unauthorized users to bypass security checks and perform actions they should not have permission to execute. If exploited, an attacker could take control of bot operations, potentially leading to unauthorized data access or system disruption. Organizations using this feature should update to the latest version immediately to restore proper access controls.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's QQBot exec approvals feature. When this feature is enabled, the application fails to properly validate the authorization of senders, allowing lower-trust callers or specific input paths to execute or persist actions beyond their intended scope. The attack is reachable over the network and requires low privileges, but no user interaction. Successful exploitation allows an attacker to bypass allowlists and perform unauthorized operations with high impact on confidentiality, integrity, and availability. The issue is resolved in version 2026.5.27.
Affected products
- OpenClaw OpenClaw 2026.5.14-beta.1 to 2026.5.27
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-17: disclosed: NVD publication date