Junglewise Threat Intelligence

OpenClaw QQBot approval button authorization bypass

Severity: low · CVSS 3.1 · Published 2026-05-29

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an automation tool that uses QQBot to deliver approval workflows for sensitive operations like script execution and plugin deployments. A flaw in the native approval button feature allows non-authorized users to click approval buttons and bypass the configured approver identity check, potentially permitting unauthorized exec or plugin actions.

Technical details

The vulnerability is a missing authorization check (CWE-862) in OpenClaw's QQBot native approval button callback path. When users interact with native approval buttons delivered to QQ conversations, the system fails to enforce the configured approver identity, unlike the text command approval path which correctly validates authorization. An attacker with visibility to an approval message but no approver privileges can click the approval button to resolve pending exec or plugin approval requests. The flaw requires network access, low privileges (a QQ user account), and user interaction (clicking a button). OpenClaw versions before 2026.5.18 are affected; users should upgrade immediately and consider disabling native approval buttons in conversations with non-approver users until patched.

Affected products

  • OpenClaw OpenClaw before 2026.5.18

Timeline

  • 2026-05-28: disclosed
  • 2026-05-18: patched: Version 2026.5.18 released
  • 2026-07-02: other: Advisory withdrawn as duplicate of GHSA-mgq6-vr84-7m2j

References

Related threats