CVE-2026-32039 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit e…
Medium CVSS: 6.0

CVE-2026-32039

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyped sender keys by forcing collisions with mutable identity values such as senderName or senderUsername to bypass sender-authorization policies and gain unauthorized access to privileged tools.
Vendor
Openclaw
Product
Openclaw
CWE
CWE-639
Yayın Tarihi
2026-03-19 22:16:40
Güncelleme
2026-03-23 17:19:19
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar