CVE-2026-31991 identifies an authorization bypass vulnerability in OpenClaw versions prior to 2026.2.26. This flaw allows an attacker, after obtaining DM pairing approval, to bypass Signal group allowlist policies and gain unauthorized group access. Rated as Medium severity with a CVSS score of 4.6, the vulnerability has a network attack vector, low attack complexity, and requires low privileges and user interaction, resulting in low impacts to confidentiality and integrity. There is currently no evidence of active exploitation, nor are public exploit codes or significant community discussion available for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.26CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.26CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.