Back to overview

CVE-2026-32975

CRITICAL
9.8
CVSS 3.1
Description
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages from unintended groups to the agent.

Metadata

CVE ID
CVE-2026-32975
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-03-17 11:31 UTC
Published
2026-03-29 12:44 UTC
Last updated
2026-06-23 16:15 UTC
Primary CWE
CWE-807
Reliance on Untrusted Inputs in a Security Decision
Vendor / Product
OpenClaw / OpenClaw
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
OpenClaw OpenClaw 0 < 2026.3.12, 2026.3.12
Weakness (CWE)
CWESourceDescription
CWE-807 cna Reliance on Untrusted Inputs in a Security Decision
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
References (2)
Back to overview