Junglewise Threat Intelligence

OpenClaw delivery queue recovery loses group tool-policy context

Severity: low · CVSS 3.1 · Published 2026-05-06

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a messaging and collaboration platform that enforces media sharing policies at the group level. During service restarts or recovery operations, queued media messages can be replayed without their original access control context, allowing previously restricted media to bypass group policy enforcement and be delivered to unintended recipients.

Technical details

The vulnerability is a missing session context persistence issue (CWE-862: missing authorization) in OpenClaw's delivery queue recovery mechanism for media replay. When the service recovers queued outbound media after a restart, it fails to restore and enforce the original session context and group tool-policy restrictions that would normally govern whether that media can be delivered. This is a local/network-adjacent issue affecting service availability and confidentiality after restart. The fix, released in version 2026.4.14, persists the relevant session context with each delivery queue entry so recovered media dispatch undergoes proper policy validation.

Affected products

  • OpenClaw OpenClaw >= 2026.4.10, < 2026.4.14

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: patched: Fixed in version 2026.4.14 (commit 48aae82bbc19ba8b0741e61a08063eb0d1df464e)

References

Related threats