CVE-2026-32067: OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.
Other sources
OpenClaw versions prior to 2026.2.26 contains an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.2.26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32067?
CVE-2026-32067 is classified as a high severity vulnerability due to the potential for unauthorized access across accounts.
How do I fix CVE-2026-32067?
To fix CVE-2026-32067, upgrade OpenClaw to version 2026.2.26 or later, which addresses the authorization bypass issue.
What type of vulnerability is CVE-2026-32067?
CVE-2026-32067 is a cross-account authorization bypass vulnerability affecting the DM Pairing Store.
Who is affected by CVE-2026-32067?
OpenClaw users running versions prior to 2026.2.26 are affected by CVE-2026-32067.
What can attackers do with CVE-2026-32067?
Attackers can reuse pairing approvals across multiple accounts due to the authorization bypass in CVE-2026-32067.