OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know an approval id. | |
| Title | OpenClaw < 2026.4.12 - Improper Authorization via Empty Approver Lists | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-183 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-05T11:25:13.823Z
Updated: 2026-05-05T12:19:57.990Z
Reserved: 2026-05-01T16:58:23.117Z
Link: CVE-2026-43574
Updated: 2026-05-05T12:19:53.633Z
Status : Received
Published: 2026-05-05T12:16:21.307
Modified: 2026-05-05T12:16:21.307
Link: CVE-2026-43574
No data.