Impact
OpenClaw versions before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. The flaw allows a caller with lower trust or a configured input path to execute or persist actions outside the intended authorization limits. This bypass can enable non‑allowlisted senders to trigger privileged commands or‑style operations, potentially compromising the confidentiality, integrity or availability of the system.
Affected Systems
The vulnerability affects the OpenClaw application distributed by OpenClaw. It is present in releases 2026.5.14‑beta.1 through 2026.5.26 and is resolved in 2026.5.27 and later. The affected component is the QQBot exec approvals service exposed over the application interface within the Node.js deployment.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. The EPSS score of <1% suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the QQBot exec approvals endpoint when the feature is enabled; the attacker must supply an identity or input path that the system considers lower trust. Because the flaw is an authorization bypass (CWE‑863), success depends on the attacker being able to reach the endpoint and craft a request that exploits the trust boundary. The overall risk for exposed deployments remains high given the impact, but the current probability of exploitation is low.
OpenCVE Enrichment