Impact
OpenClaw versions prior to 2026.6.9 suffer from a missing authorization check in Discord moderation actions. The flaw allows a caller with lower trust or an externally supplied input path to execute moderation commands that would normally require higher privileges or a stricter policy check. The resulting impact is an unauthorized ability to perform moderation actions such as bans, mutes, or message deletions, potentially harming users or disrupting server operations. The severity of the practical results relies on how a lower‑trust input can reach the vulnerable pathway, but the flaw clearly enables escalation of privileges within the bot's control domain.
Affected Systems
The vulnerability applies to the OpenClaw project, specifically the OpenClaw software. All releases dated earlier than version 2026.6.9 are affected. Users operating those earlier releases are at risk if their configuration allows lower‑trust callers or if untrusted input can be supplied to the moderation functionality.
Risk and Exploitability
The CVSS score of 6 indicates moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector would involve crafting a request to a Discord moderation endpoint that OpenClaw processes, using an unprivileged or compromised input to trigger the action. Successful exploitation requires that the attacker can supply such a request or that lower‑trust input paths are not adequately filtered, allowing the bot to act on commands without the required authorization.
OpenCVE Enrichment