Impact
OpenClaw versions before 2026.5.7 contain a flaw in the allowFrom feature where the application verifies Discord identities by comparing mutable display names instead of permanently assigned user IDs. This improper check allows an attacker who controls any Discord account to change their display name to match an entry in the allowFrom list, thereby gaining agent access that was intended for a different user. The vulnerability is classified as CWE‑290, indicating an authorization bypass via inadequate identity verification.
Affected Systems
The affected product is OpenClaw, all releases prior to 2026.5.7. The CVE specifies that any instance running an older version is susceptible; no specific operating systems or deployment environments are singled out beyond the standard node.js runtime.
Risk and Exploitability
The CVSS score of 8.6 signals high severity, while the EPSS score is below 1%, suggesting a low current exploitation probability. The vulnerability is not present in the CISA KEV catalog. An attacker who can control a Discord account can perform the display name change locally, then request access via the compromised OpenClaw instance, escalating privileges on that system. The most likely attack vector is social engineering or account compromise, with no network-wide prerequisite beyond access to the Discord account.
OpenCVE Enrichment