Policy Bypass Vulnerability in OpenClaw QQBot Admin Commands
CVE-2026-34507

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-34507?

An identified policy bypass vulnerability exists in OpenClaw prior to version 2026.4.29, impacting the QQBot’s administrative command functions. This vulnerability allows authenticated users to circumvent critical DM-only and allowFrom policy validations, enabling potentially unauthorized senders to execute admin commands that should be restricted. The risk stems from the ability of adversaries to exploit this flaw, leading to actions that should otherwise be controlled by existing security measures.

Affected Version(s)

OpenClaw 0 < 2026.4.29

OpenClaw 2026.4.29

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dikai Zou
.