Improper Authorization Vulnerability in OpenClaw by OpenClaw
CVE-2026-43574

6MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-43574?

OpenClaw versions prior to 2026.4.12 are vulnerable to an improper authorization issue within helper-backed channels. This vulnerability arises from the incorrect handling of empty resolved approver lists, which are mistakenly treated as explicit approvals. Malicious actors can exploit this flaw by knowing a specific approval ID, allowing them to resolve pending approvals without legitimate authorization. This security oversight poses significant risks and necessitates immediate attention from users to mitigate potential exploitation.

Affected Version(s)

OpenClaw 0 < 2026.4.12

OpenClaw 2026.4.12

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anshuman Bhartiya (@anshumanbh)
.