Junglewise Threat Intelligence

OpenClaw Google Chat authorization bypass via group policy rebinding

Severity: low · CVSS 3.1 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a library used to manage Google Chat group policies and access control. A vulnerability in its policy enforcement allows attackers with limited user access to bypass authorization checks by manipulating group display names, potentially gaining unauthorized access to protected resources and data that should be restricted by group policies.

Technical details

OpenClaw versions up to 2026.3.24 implement group authorization decisions based on mutable space display names, which can be changed or collided by users. An attacker with standard user privileges can manipulate or rebind group policies by altering display names, bypassing the intended authorization controls (CWE-807, CWE-639, CWE-863). The vulnerability requires user authentication but is remotely exploitable over the network. Fix: commit 11ea1f67863d88b6cbcb229dd368a45e07094bff in version 2026.3.25 replaces mutable display name-based policy decisions with stable group IDs.

Affected products

  • OpenClaw OpenClaw up to 2026.3.24

Timeline

  • 2026-03-26: disclosed
  • 2026-03-26: patched: Fixed in version 2026.3.25
  • 2026-04-10: advisory

References

Related threats