Vulnerability in OpenClaw Personal AI Assistant Affecting Group Authorization
CVE-2026-26328
6.5MEDIUM
What is CVE-2026-26328?
OpenClaw, a personal AI assistant, exhibits a vulnerability where group authorization can be improperly satisfied by sender identities sourced from the device management (DM) pairing store. This unintended behavior allows broader trust contexts, potentially leading to unauthorized access or actions within group settings. The issue has been addressed in version 2026.2.14 to enhance group policy security under iMessage.
Affected Version(s)
clawdbot <= 2026.1.24-3
openclaw < 2026.2.14
