Improper Authorization Vulnerability in OpenClaw by OpenClaw
CVE-2026-43574
6MEDIUM
What is CVE-2026-43574?
OpenClaw versions prior to 2026.4.12 are vulnerable to an improper authorization issue within helper-backed channels. This vulnerability arises from the incorrect handling of empty resolved approver lists, which are mistakenly treated as explicit approvals. Malicious actors can exploit this flaw by knowing a specific approval ID, allowing them to resolve pending approvals without legitimate authorization. This security oversight poses significant risks and necessitates immediate attention from users to mitigate potential exploitation.
Affected Version(s)
OpenClaw 0 < 2026.4.12
OpenClaw 2026.4.12
