Executive brief
OpenClaw is a framework that integrates Mattermost (team communication software) with AI capabilities. The vulnerability allows attackers to send specially crafted Mattermost events that bypass intended security policies designed to gate certain operations. By omitting channel type information, attackers can process messages that should have been blocked, potentially exposing restricted content or triggering unintended actions.
Technical details
This is an improper access control vulnerability (CWE-636: Not Failing Securely) in OpenClaw's Mattermost event handlers. The root cause is missing validation of the channel type metadata in incoming Mattermost events. When a Mattermost event lacks channel type information, the handler fails to apply intended access control policies and proceeds unsafely. The attack is network-reachable and requires no authentication or user interaction, though it has moderately high attack complexity due to prerequisite conditions (attack requirements present). A successful exploit allows an attacker to process a Mattermost event that should have been blocked by channel policy, potentially accessing or modifying restricted content depending on the operator's configuration. The vulnerability is patched in version 2026.5.6.
Affected products
- OpenClaw OpenClaw < 2026.5.6
Timeline
- 2026-05-28: disclosed
- 2026-06-12: advisory
- 2026-05-28: patched: Patched version 2026.5.6 available