Access Control Vulnerability in OpenClaw Product by OpenClaw
CVE-2026-32050
6.3MEDIUM
What is CVE-2026-32050?
OpenClaw prior to version 2026.2.25 is susceptible to an access control vulnerability that compromises signal reaction notification handling. This flaw allows unauthorized senders to enqueue status events without passing necessary authorization checks. Attackers can effectively exploit this vulnerability via the reaction-only event path located in event-handler.ts, leading to the queuing of signal reaction status lines for sessions lacking proper DM or group access validation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenClaw 0 < 2026.2.25
OpenClaw 2026.2.25
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
tdjackey
