Authorization Bypass Vulnerability in OpenClaw Affecting QQBot Functionality
CVE-2026-35630
7.5HIGH
What is CVE-2026-35630?
OpenClaw versions prior to 2026.5.18 contain an authorization bypass issue within QQBot's native approval buttons. This flaw allows users without proper authorization to interact with approval buttons, enabling them to resolve pending executive or plugin approval requests without the necessary permissions. This vulnerability poses a significant risk as it undermines the integrity of approval processes, potentially allowing unauthorized actions to occur in the system.
Affected Version(s)
OpenClaw 0 < 2026.5.18
OpenClaw 2026.5.18
