Junglewise Threat Intelligence

OpenClaw authorization bypass in Signal group allowlist

Severity: low · CVSS 3.1 · Published 2026-03-19

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a messaging library used to manage Signal group access controls. A weakness in the authorization logic allows attackers who have obtained approval for direct message (DM) pairing to bypass group allowlist restrictions and gain unauthorized access to restricted groups, compromising group membership boundaries.

Technical details

The vulnerability is an incorrect authorization check (CWE-863) in OpenClaw versions prior to 2026.2.26. The group allowlist policy incorrectly accepts sender identities from the DM pairing-store instead of enforcing explicit group allowlist boundaries. An attacker who obtains DM pairing approval can exploit this boundary weakness to pass group allowlist checks without being explicitly added to the group allowlist. The attack requires network access, low privileges (DM pairing approval), and user interaction (DM pairing flow). Patches are available in version 2026.2.26 and later, which enforce proper separation between DM pairing-store entries and group policy resolution.

Affected products

  • OpenClaw OpenClaw <= 2026.2.25

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: patched: Version 2026.2.26 and later
  • 2026-03-19: advisory

References

Related threats