โ† Back to all CVEs

CVE-2026-32898

MEDIUM openclaw NVD
CVSS Score 5.4
Severity MEDIUM
Published Mar 21, 2026
Vendor openclaw

Description

OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive approval prompts for read-class operations by spoofing tool metadata or using non-core read-like names to reach auto-approve paths.

References