CVE-2026-32067
high
CVSS v3
8.1
CVSS v2
—
VIR risk
8.1
Description
OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Predictions
Exploit likelihood
88%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/security/advisories/GHSA-vjp8-wprm-2jw9
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/bce643a0bd145d3e9cb55400af33bd1b85baeb02
Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/a0c5e28f3bf0cc0cd9311f9e9ec2ca0352550dcf
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | openclaw | <2026.2.26 | 2026.2.26 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openclaw | openclaw | {"endExcluding":"2026.2.26"} | 2026.2.26 |
References
- https://github.com/openclaw/openclaw/commit/a0c5e28f3bf0cc0cd9311f9e9ec2ca0352550dcf
- https://github.com/openclaw/openclaw/commit/bce643a0bd145d3e9cb55400af33bd1b85baeb02
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vjp8-wprm-2jw9
- https://www.vulncheck.com/advisories/openclaw-cross-account-authorization-bypass-in-dm-pairing-store
- https://nvd.nist.gov/vuln/detail/CVE-2026-32067
- https://github.com/openclaw/openclaw
CWEs
CWE-863
Verify integrity in audit chain (admin only). AS-IS.