Количество 2
Количество 2
CVE-2026-32006
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send messages and reactions as DM-paired identities without explicit groupAllowFrom membership to bypass group sender authorization checks.
GHSA-25pw-4h6w-qwvm
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-32006 OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send messages and reactions as DM-paired identities without explicit groupAllowFrom membership to bypass group sender authorization checks. | CVSS3: 3.1 | 0% Низкий | 4 месяца назад | |
GHSA-25pw-4h6w-qwvm OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу