Impact
OpenClaw before 2026.5.19 contains an authorization bypass in message read actions that skips channel allowlist checks. This flaw allows callers with lower trust levels to request messages from channels that are not intended for them, potentially exposing sensitive channel content. The weakness falls under CWE-862, representing missing authorization controls.
Affected Systems
Vendors: OpenClaw. Product: OpenClaw. Versions affected are any releases before 2026.5.19. No additional version details are provided beyond the cutoff mentioned.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high severity vulnerability. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote API calls to the message read endpoint, which would require authentication but can bypass internal channel authorization. Attackers may exploit this to read confidential messages from unauthorized channels.
OpenCVE Enrichment