Junglewise Threat Intelligence

OpenClaw QQBot authorization bypass in admin commands

Severity: critical · CVSS 9.3 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and plugin system, contains a vulnerability in its QQBot integration where administrative commands can bypass security policies. Specifically, commands that should be restricted to private direct messages or specific senders can be triggered from unauthorized contexts. This could allow an unauthorized user to execute administrative actions, potentially leading to full system compromise or unauthorized data access depending on the bot's configuration.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in OpenClaw's QQBot component. In affected versions, exported admin commands fail to properly enforce 'DM-only' (Direct Message only) and 'allowFrom' (sender allowlist) policies. A remote attacker capable of triggering these exported commands can route administrative requests through unauthorized channels or from unauthorized accounts, bypassing intended access controls. The vulnerability is exploitable over the network without prior privileges or user interaction. A fix is available in version 2026.4.29.

Affected products

  • openclaw openclaw < 2026.4.29

Timeline

  • 2026-05-28: disclosed
  • 2026-04-29: patched: First stable patched version released.
  • 2026-07-02: advisory

References

Related threats