Policy Bypass Vulnerability in OpenClaw QQBot Admin Commands
CVE-2026-34507
2.3LOW
What is CVE-2026-34507?
An identified policy bypass vulnerability exists in OpenClaw prior to version 2026.4.29, impacting the QQBot’s administrative command functions. This vulnerability allows authenticated users to circumvent critical DM-only and allowFrom policy validations, enabling potentially unauthorized senders to execute admin commands that should be restricted. The risk stems from the ability of adversaries to exploit this flaw, leading to actions that should otherwise be controlled by existing security measures.
Affected Version(s)
OpenClaw 0 < 2026.4.29
OpenClaw 2026.4.29
