CVE-2026-31998Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can bypass authorization checks and trigger unauthorized agent dispatch and downstream tool actions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-03-19); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-19: 5Mentions · 2026-03-21: 1Technical Details · 2026-03-19: 403-1903-21
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-195
Disclosure4General1
2026-03-211
Disclosure1
Full discourse6 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-31998 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-31998-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-31998 #openclaw #

    Post summary

    The post merely publishes a link to a CVE alert for CVE-2026-31998, offering no additional details on exploitation, fixes, or technical aspects.

    1000082
    3.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31998 📊 Severity: 7.0 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31998 #CVE-2026-31998 #CVE #High  #CyberSecurity #InfoSec https://t.co/r6qOfnc5qS

    Post summary

    The tweet announces a new CVE (CVE-2026-31998) with a severity score of 7.0 and high risk level, providing a link to the NVD, but offers no further technical details or additional information.

    0000028
    108 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    🚨 6 high-severity CVEs dropped today for OpenClaw - the popular AI automation platform CVE-2026-28461 (7.5) - Memory exhaustion via webhook CVE-2026-31989 (7.4) - SSRF via web_search CVE-2026-27566 (7.1) - Allowlist bypass CVE-2026-31992 (7.1) - Exec-guard bypass CVE-2026-31994 (7.1) - Command injection CVE-2026-31998 (7.0) - Auth bypass Popular platforms = bigger targets. Track everything: http://vulntracker.io

    Post summary

    The tweet announces six high‑severity CVEs affecting OpenClaw, listing their CVSS scores and technical types, but provides no PoC, exploit code, or patch information.

    00000124
    433 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31998 OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty… https://www.cve.org/CVERecord?id=CVE-2026-31998

    Post summary

    The statement discloses an authorization bypass vulnerability in OpenClaw's synology-chat channel plugin affecting specific versions.

    00000130
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31998 Authorization Bypass in OpenClaw Synology-Chat Plugin Enabling Unauthorized Agent Dispatch https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31998

    Post summary

    A new authorization bypass vulnerability (CVE-2026-31998) in the OpenClaw Synology-Chat plugin allows unauthorized agent dispatch, as reported on Vulmon.

    0000054
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31998 - OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds Intel Report: http://blog.cyberdudebivash.com/2026/03/cve-2026-31998-openclaw-2026222-2026224.html

    Post summary

    The message announces CVE-2026-31998, detailing an authorization bypass vulnerability in Synology Chat Plugin, but does not mention exploits, patches, or activity.

    0000089
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more