


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. No…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 18:02:16
Source:
nvd.nist.gov
Identity & Access, Security Tools
OpenClaw versions before 2026.5.18 contain a critical authorization bypass vulnerability in QQBot native approval buttons. The vulnerability fails to enforce configured approver identity, allowing non-approver users to click approval buttons and resolve pending exec or plugin approval requests without proper authorization. This represents a significant security flaw that could allow unauthorized users to approve sensitive operations and bypass established approval workflows.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35630
https://github.com/openclaw/openclaw/security/advisories/GHSA-mgq6-vr84-7m2j
https://www.vulncheck.com/advisories/openclaw-qqbot-missing-approver-identity-enforcement-in-native-approval-buttons
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
