Authorization Bypass Vulnerability in OpenClaw Affecting QQBot Functionality
CVE-2026-35630

7.5HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-35630?

OpenClaw versions prior to 2026.5.18 contain an authorization bypass issue within QQBot's native approval buttons. This flaw allows users without proper authorization to interact with approval buttons, enabling them to resolve pending executive or plugin approval requests without the necessary permissions. This vulnerability poses a significant risk as it undermines the integrity of approval processes, potentially allowing unauthorized actions to occur in the system.

Affected Version(s)

OpenClaw 0 < 2026.5.18

OpenClaw 2026.5.18

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dikai Zou
.