OpenClaw Authorization Bypass Vulnerability in Discord Text Approval Commands
Vulnerability
An authorization bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.28. This vulnerability allows non-approvers to resolve pending execution approvals by sending Discord text commands that bypass the approver allowlist. As a result, unauthorized users can approve pending host execution requests.
Impact
Exploitation of this vulnerability allows non-approvers to approve pending execution requests on hosts, potentially leading to unauthorized execution of commands or scripts.
Remediation
Users can upgrade to OpenClaw version 2026.3.28 or later to address this vulnerability.
Added: Apr 21, 2026, 12:22 AM
Updated: Apr 21, 2026, 12:22 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
3.1exploitability
5.2remediation
0.0relevance
6.4threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
