Vulnerability in OpenClaw Personal AI Assistant Affecting Group Authorization
CVE-2026-26328
6.5MEDIUM
What is CVE-2026-26328?
OpenClaw, a personal AI assistant, exhibits a vulnerability where group authorization can be improperly satisfied by sender identities sourced from the device management (DM) pairing store. This unintended behavior allows broader trust contexts, potentially leading to unauthorized access or actions within group settings. The issue has been addressed in version 2026.2.14 to enhance group policy security under iMessage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
clawdbot <= 2026.1.24-3
openclaw < 2026.2.14
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
