Junglewise Threat Intelligence

OpenClaw authorization bypass in Telegram interactive callbacks

Severity: high · CVSS 8.8 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway tool, contains a security flaw in how it handles Telegram interactive commands. An unauthorized user could bypass the configured sender allowlist, potentially executing commands they should not have access to. This could lead to unauthorized operations or data access depending on how the gateway is configured.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's Telegram integration. In affected versions, interactive callbacks can be marked as authorized before the 'commands.allowFrom' allowlist is applied. This allows a remote, unauthenticated Telegram user to bypass sender restrictions if the interactive callback feature is enabled. Attackers can trigger command behaviors that should be restricted to specific authorized senders. The issue is resolved in version 2026.5.6.

Affected products

  • openclaw openclaw <= 2026.5.5

Timeline

  • 2026-05-28: disclosed
  • 2026-07-02: advisory
  • 2026-05-28: patched: First stable patched version is 2026.5.6

References

Related threats