Impact
OpenClaw versions 2026.3.22 through, but not including, 2026.6.6 contain an authorization bypass that lets a lower‑trust user satisfy an elevated sender allowlist by leveraging WhatsApp group IDs. The flaw enables attackers to perform actions normally reserved for higher‑level permissions, thereby compromising the integrity of privileged operations. The vulnerability is classified as CWE‑863 (Authorization Bypass Through User‑Controlled Key).
Affected Systems
The OpenClaw application is affected, specifically versions released 2026.3.22 and any earlier than 2026.6.6. All deployments running these versions are susceptible to the bypass unless the feature is disabled or reconfigured.
Risk and Exploitability
The CVSS score of 8.7 places the issue in the high severity range. The EPSS score of less than 1% indicates a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to interact with the application’s message handling interface to submit a WhatsApp group ID that is present in the elevated sender allowlist. The vector is inferred to be remote, as the attacker must submit a message to the application’s interface, but this is not explicitly stated in the advisory. The combination of a high severity rating and the privilege escalation potential therefore poses a significant risk for affected deployments.
OpenCVE Enrichment