CVE-2026-32923
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails to enforce member users and roles allowlist checks. Non-allowlisted guild members can trigger reaction events accepted as trusted system events, injecting reaction text into downstream session context.
Vendor
Product
CWE
Yayın Tarihi
2026-03-29 13:17:00
Güncelleme
2026-03-31 18:01:13
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-