Executive brief
OpenClaw is a tool management platform that uses group-based access policies to control who can invoke certain tools. A flaw in the policy enforcement logic accepts unvalidated group identifiers, allowing an authenticated attacker to trigger incorrect access control decisions and potentially invoke tools they should not have permission to use.
Technical details
OpenClaw versions before 2026.4.25 fail to validate group identifiers supplied to the tool group policy resolver, leading to authorization bypass. The vulnerability exists in the policy caller component that determines whether a user can invoke a tool based on group membership. An authenticated attacker with network access to the affected feature can supply an arbitrary group ID, causing the policy resolver to make incorrect group-policy decisions for tool invocation. The impact depends on operator configuration and the sensitivity of tools protected by group policy. Patch available in version 2026.4.25 and later.
Affected products
- OpenClaw OpenClaw before 2026.4.25
Timeline
- 2026-05-28: disclosed
- 2026-06-16: advisory
- 2026-04-25: patched: Version 2026.4.25 contains the fix