Vulnerability Description
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAllowFrom and requireMention protections in group chat reaction-derived events.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.3.12 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-m69h-jm2f-2pv8Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-misclassiThird Party Advisory
FAQ
What is CVE-2026-32924?
CVE-2026-32924 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers ca...
How severe is CVE-2026-32924?
CVE-2026-32924 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-32924?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.