CVE-2026-22170
MEDIUMOpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom Configuration
Title source: cnaDescription
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attackers can send direct messages to BlueBubbles accounts by exploiting the misconfigured allowlist validation logic to bypass intended sender authorization checks.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-jwf4-8wf4-jf2m)
https://github.com/openclaw/openclaw/security/advisories/GHSA-jwf4-8wf4-jf2m
Patch patch
Patch Commit #1
https://github.com/openclaw/openclaw/commit/9632b9bcf032c5f2280c3103961fde912ab1f920
Patch patch
Patch Commit #2
https://github.com/openclaw/openclaw/commit/2ba6de7eaad812e5e8603018e14e54e96bdd57dd
Patch patch
Patch Commit #3
https://github.com/openclaw/openclaw/commit/51c0893673de8e5cea64e64351dbfa4680ba0dec
Patch patch
Patch Commit #4
https://github.com/openclaw/openclaw/commit/4540790cb62412676f7b61cfc6e47443f84a251e
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom Configuration
https://www.vulncheck.com/advisories/openclaw-bluebubbles-access-control-bypass-via-empty-allowfrom-configuration
Scores
CVSS v3
6.5
EPSS
0.0026
EPSS Percentile
16.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (3)
npm/openclaw
0 - 2026.2.22npm
OpenClaw/OpenClaw
< 2026.2.22
openclaw/openclaw
< 2026.2.22
Published
Mar 18, 2026
Tracked Since
Mar 18, 2026