CVE-2026-31998 is a critical authorization bypass vulnerability affecting OpenClaw versions 2026.2.22 and 2026.2.23, specifically within the synology-chat channel plugin. This flaw allows remote, unauthenticated attackers to bypass authorization checks and trigger unauthorized agent dispatch and downstream tool actions when the dmPolicy is set to an empty allowlist. Rated 9.8 CVSS (Critical), it poses a high risk to confidentiality, integrity, and availability due to its low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2026.2.22, < 2026.2.24CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.