Impact
OpenClaw versions 2026.6.6 up to but excluding 2026.6.9 have a flaw that lets callers with lower trust levels perform privileged Discord guild actions that normally would be protected by cross‑provider requester authorization. This is an authorization bypass that can lead to unintended operations, potentially exposing data or taking control of guild functions, classified as CWE‑863.
Affected Systems
All releases of the OpenClaw application distributed prior to 2026.6.9, including 2026.6.6, 2026.6.7, and 2026.6.8, built on Node.js. The vulnerability affects the Discord guild action handlers implemented in the OpenClaw code base.
Risk and Exploitability
The CVSS score of 7.2 ranks the flaw as high severity. The EPSS score is reported as less than 1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires an attacker to send crafted requests that manipulate the path parameters used by Discord guild actions to bypass the missing authorization check. The likely attack vector is remote, through network requests to the OpenClaw service, enabled by Discord interactions that an attacker could trigger. Once the bypass is achieved, the attacker can execute restricted operations that should be confined to higher‑trust users.
OpenCVE Enrichment