CVE-2026-32067
LOWOpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store
Title source: cnaDescription
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-vjp8-wprm-2jw9)
https://github.com/openclaw/openclaw/security/advisories/GHSA-vjp8-wprm-2jw9
Patch patch
Patch Commit #1
https://github.com/openclaw/openclaw/commit/a0c5e28f3bf0cc0cd9311f9e9ec2ca0352550dcf
Patch patch
Patch Commit #2
https://github.com/openclaw/openclaw/commit/bce643a0bd145d3e9cb55400af33bd1b85baeb02
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store
https://www.vulncheck.com/advisories/openclaw-cross-account-authorization-bypass-in-dm-pairing-store
Scores
CVSS v3
3.7
EPSS
0.0016
EPSS Percentile
6.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (4)
npm/openclaw
0 - 2026.2.26npm
OpenClaw/OpenClaw
< 2026.2.26
openclaw/openclaw
< 2026.2.26
OpenClaw/OpenClaw
2026.2.26
Published
Mar 21, 2026
Tracked Since
Mar 21, 2026