Back

HIGH

OpenClaw 2026.2.22 < 2026.2.24 - Authorization Bypass in Synology Chat Plugin via Empty allowedUserIds

Published Mar 19, 2026

Description

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can bypass authorization checks and trigger unauthorized agent dispatch and downstream tool actions.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
CISA Vulnrichment
Updated Mar 19, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Exploited since n/a
EUVD-2026-13035 GHSA-GW85-XP4Q-5GP9