Executive brief
OpenClaw, a media delivery platform, contains a flaw where security policies are not correctly reapplied to media files waiting in a delivery queue after a system restart. This allows an attacker to bypass intended media restrictions and group policies, potentially leading to unauthorized content distribution. Organizations using affected versions should update to ensure that security controls remain active during service recovery.
Technical details
A missing authorization vulnerability (CWE-862) exists in OpenClaw's outbound delivery queue. The application fails to persist and replay the original session context when recovering queued outbound media after a service restart or recovery event. An attacker with low privileges can exploit this by ensuring media is queued and then processed post-recovery, bypassing group tool policy enforcement and weakening channel media restrictions. The vulnerability is triggered during the media dispatch phase where the system fails to verify the original policy context. A fix is available in version 2026.4.14 which ensures session context is persisted with queue entries.
Affected products
- OpenClaw openclaw >= 2026.4.10, < 2026.4.14
Timeline
- 2026-04-16: advisory: Original vendor advisory GHSA-r77c-2cmr-7p47 published
- 2026-05-06: disclosed: CVE-2026-43583 published to NVD
- 2026-05-12: patched: Duplicate advisory GHSA-82rm-qcfx-2v78 withdrawn in favor of original report