OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can execute room control commands without being in configured allowlists by posting in bot rooms, potentially enabling privileged OpenClaw behavior.
References
Configurations
History
No history.
Information
Published : 2026-05-06 20:16
Updated : 2026-06-17 10:50
NVD link : CVE-2026-44110
Mitre link : CVE-2026-44110
CVE.ORG link : CVE-2026-44110
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
