CVE-2026-32975 identifies a critical weak authorization vulnerability (CVSS 9.8) in OpenClaw versions prior to 2026.3.12. This flaw allows attackers to bypass channel authorization by creating groups with display names identical to allowlisted groups, due to the system matching mutable names instead of stable identifiers. Exploitable over the network with low complexity, this vulnerability can lead to high impact on confidentiality, integrity, and availability by routing messages from unintended groups to agents. Currently, there is no evidence of active exploitation, nor is public exploit code available, though the vulnerability has generated some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.12CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.12CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.