OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-jp4j-q5fc-58gv | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-policy-enforcement-bypass-in-discord-component-interactions | Third Party Advisory |
Configurations
History
28 Apr 2026, 18:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
|
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-jp4j-q5fc-58gv - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-policy-enforcement-bypass-in-discord-component-interactions - Third Party Advisory |
28 Apr 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 00:16
Updated : 2026-04-28 18:45
NVD link : CVE-2026-41367
Mitre link : CVE-2026-41367
CVE.ORG link : CVE-2026-41367
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
