MEDIUM
OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions
Published Apr 27, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.28%
Description
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.
Affected products
-
- Version 2026.2.14StatusaffectedConstraints<2026.3.28
- Version 2026.3.28StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 2026.2.14 Fixed 2026.3.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 2026.2.14 | 2026.3.28 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/openclaw/openclaw/security/advisories/GHSA-jp4j-q5fc-58gv vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-policy-enforcement-bypass-in-discord-component-interactions third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-jp4j-q5fc-58gv | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-policy-enforcement-bypass-in-discord-component-interactions | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 27, 2026
Updated May 25, 2026
Reserved Apr 20, 2026
Link CVE-2026-41367
CISA Vulnrichment
Updated Apr 28, 2026