Description
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have blocked.
Published: 2026-05-29
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions prior to 2026.4.29 contain a policy bypass flaw in the QQBot admin command module. The vulnerability allows an authenticated sender to bypass the DM‑only and allowFrom policy checks that normally restrict when and from whom administrative commands can be issued. As a result, an attacker who has legitimate access to the system can route privileged commands from unauthorized contexts and execute behaviors that the policy should otherwise block, compromising the integrity of the bot.

Affected Systems

The affected product is OpenClaw's QQBot component, distributed under the OpenClaw brand. All installations running a release older than 2026.4.29 are susceptible to the bypass, including earlier releases such as 2026.4.28 and earlier. No specific sub‑module or variation is known to mitigate this issue, so all standard OpenClaw deployments are listed as impacted.

Risk and Exploitability

With a CVSS score of 2.3, the vulnerability is considered low severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating that widespread exploitation is not currently reported. However, the vulnerability requires only that an attacker be authenticated to the system and can create a message that satisfies the bot’s parsing, meaning the attack path is straightforward for users with access to the bot. An attacker could thus execute privileged commands that the policy should not allow, potentially altering bot configuration, permissions, or data handling.

Generated by OpenCVE AI on May 29, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.4.29 or later to receive the fixed admin‑command policy checks.
  • Configure QQBot to enforce DM‑only and allowFrom restrictions for all administrative commands; consider disabling admin command capability over direct messages entirely.
  • Apply fine‑grained access controls by restricting admin command usage to a whitelist of user IDs or roles, and monitor command logs for unauthorized attempts.

Generated by OpenCVE AI on May 29, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have blocked.
Title OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-29T17:17:17.992Z

Reserved: 2026-03-30T13:51:47.549Z

Link: CVE-2026-34507

cve-icon Vulnrichment

Updated: 2026-05-29T17:15:24.224Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-29T16:16:25.950

Modified: 2026-05-29T16:29:34.540

Link: CVE-2026-34507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T19:45:06Z

Weaknesses