CVE-2026-32021
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist implementation that accepts mutable sender display names instead of enforcing ID-only matching. An attacker can set a display name equal to an allowlisted ID string to bypass authorization checks and gain unauthorized access.
Vendor
Product
CWE
Yayın Tarihi
2026-03-19 22:16:36
Güncelleme
2026-03-25 15:16:44
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-