Executive brief
OpenClaw's Feishu integration allows workspace administrators to manage permissions and restrict access to sensitive features across users. A flaw in per-account disablement controls permits lower-privileged users or external input to bypass intended authorization checks and perform actions that should require elevated privileges. This could allow unauthorized access to sensitive operations, depending on how the integration is configured and deployed.
Technical details
This vulnerability is a CWE-863 incorrect authorization flaw in the Feishu permission tools module of OpenClaw. The root cause is inadequate enforcement of per-account disablement settings, allowing lower-trust callers or configured input paths to bypass intended authorization checks. The attack requires the feature to be enabled and reachable via network or local input; exploitation does not require user interaction or elevated attacker privileges (only low-privilege authenticated access). Successful exploitation permits actions that should have been gated by stronger policy checks, potentially exposing sensitive operations. The issue is fixed in OpenClaw version 2026.6.9 and later.
Affected products
- OpenClaw @openclaw/feishu < 2026.6.9-beta.1
Timeline
- 2026-06-30: disclosed
- 2026-09-03: advisory
- 2026-06-30: patched: First patched version: 2026.6.9