Executive brief
OpenClaw, a tool for managing automated commands and replies, contains a security flaw where unauthorized users can execute restricted administrative commands. If a channel is configured to accept messages from anyone but also has 'owner-only' command restrictions, the system may fail to distinguish between the true owner and a regular user. This allows an attacker to potentially change configurations, send unauthorized messages, or access debugging information that should be private.
Technical details
An authorization bypass vulnerability exists in OpenClaw's `command-auth.ts` component. The flaw occurs when a channel plugin has `enforceOwnerForCommands` enabled and uses a wildcard `allowFrom: ["*"]` setting without a specific `commands.ownerAllowFrom` configuration. In this scenario, the system incorrectly treats the wildcard sender policy as a valid authorization for owner-only commands. A remote attacker with basic access to the channel can execute sensitive slash commands such as `/send`, `/config`, or `/debug`. The issue was resolved in version 2026.4.21 by requiring a concrete owner identity or internal admin scope for owner-enforced commands.
Affected products
- OpenClaw openclaw < 2026.4.21
Timeline
- 2026-04-22: advisory: Original GHSA-c28g-vh7m-fm7v published
- 2026-05-11: disclosed: CVE-2026-44991 published
- 2026-05-18: other: Duplicate advisory GHSA-p3pv-c954-9m6f withdrawn
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-c28g-vh7m-fm7v
- https://github.com/openclaw/openclaw/commit/2aa93d44a1b2c7058c371f261fda2b5d4de4a882
- https://github.com/openclaw/openclaw/commit/995febb7b1e811ff6a1df5b18c22de94103f4c9f
- https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-owner-enforced-commands-via-wildcard-channel-senders