CVE-2026-32895Patch(openclaw / openclaw)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allowlists by sending system events from non-allowlisted senders through message_changed, message_deleted, and thread_broadcast events.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-25: 2Patch / Workaround · 2026-03-25: 2Technical Details · 2026-03-21: 2Technical Details · 2026-03-25: 103-2103-25
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure1General1
2026-03-252
Patch2
Full discourse4 posts
  • subagentic.ai@subagentic
    Patch

    OpenClaw CVE-2026-32895: authorization bypass in all versions before 2026.2.26. Attackers can bypass channel allowlists via system event handlers. CVSS 5.3 Medium. Patch now.

    Post summary

    OpenClaw CVE-2026-32895 is an authorization bypass affecting all versions prior to 2026.2.26, enabling attackers to bypass channel allowlists via system event handlers; the issue has a CVSS score of 5.3 Medium and a patch is now available.

    1000037
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32895 OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqu… https://www.cve.org/CVERecord?id=CVE-2026-32895

    Post summary

    The CVE record notes a sender‑authorization flaw in OpenClaw event handlers affecting versions prior to 2026.2.26, but provides no PoC, exploit, or patch details.

    00010102
    56.8K followersView on X
  • subagentic.ai@subagentic
    Patch

    Full breakdown of the vulnerability, what's exposed, and how to update: https://subagentic.ai/posts/openclaw-cve-2026-32895-authorization-bypass-patch-now/ #AgenticAI #Security

    Post summary

    A link is provided to a post offering a breakdown and update guidance for CVE‑2026‑32895, indicating the availability of a patch but lacking detailed technical or exploitation information.

    0000062
    3 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-32895 OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqu… https://www.cve.org/CVERecord?id=CVE-2026-32895 ----- Traducción: CVE-2026-32895 Ope… http://infoflow.cloud`

    Post summary

    The post cites CVE‑2026‑32895 and provides a brief technical description of the authorization flaw, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000024
    61 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more