CVE-2026-44991

medium
Published 2026-05-11 · Modified 2026-05-19
CVSS v3
4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v2
VIR risk
4.2

Description

OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners

Predictions

Exploit likelihood
52%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-owner-enforced-commands-via-wildcard-channel-senders

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/995febb7b1e811ff6a1df5b18c22de94103f4c9f

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/2aa93d44a1b2c7058c371f261fda2b5d4de4a882

Package impact

EcosystemPackageVulnerableFixed
npm npmopenclaw<2026.4.212026.4.21
npm NPMopenclaw<= 2026.4.202026.4.21

Application impact

VendorProductVersionsFixed
openclawopenclaw{"endExcluding":"2026.4.21"}2026.4.21

References

CWEs

CWE-863

Verify integrity in audit chain (admin only). AS-IS.