CVE-2026-31991
LOWOpenClaw < 2026.2.26 - Authorization Bypass via DM Pairing-Store Leakage in Signal Group Allowlist
Title source: cnaDescription
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy incorrectly accepts sender identities from DM pairing-store approvals. Attackers can exploit this boundary weakness by obtaining DM pairing approval to bypass group allowlist checks and gain unauthorized group access.
Scores
CVSS v3
3.7
EPSS
0.0004
EPSS Percentile
11.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-863
Status
published
Products (3)
npm/openclaw
0 - 2026.2.26npm
OpenClaw/OpenClaw
< 2026.2.26
openclaw/openclaw
< 2026.2.26
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026