CVE-2026-32924: OpenClaw < 2026.3.12 - Authorization Bypass via Misclassified Reaction Events in Feishu

Published Mar 29, 2026
·
Updated

OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chattype are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAllowFrom and requireMention protections in group chat reaction-derived events.

Affected Software

2 affected components
OpenClaw<2026.3.12
OpenClaw Openclaw Node.js<2026.3.12

Event History

Mar 29, 2026
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-32924?

CVE-2026-32924 has a high severity rating due to its potential to allow unauthorized access to user conversations.

2

How do I fix CVE-2026-32924?

To fix CVE-2026-32924, upgrade to OpenClaw version 2026.3.12 or later, which addresses the authorization bypass issue.

3

What software is affected by CVE-2026-32924?

CVE-2026-32924 affects OpenClaw versions prior to 2026.3.12.

4

What exploit can attackers perform using CVE-2026-32924?

Attackers can exploit CVE-2026-32924 to bypass authorization and access p2p conversations misclassified as group chats.

5

Is CVE-2026-32924 related to any specific features of OpenClaw?

CVE-2026-32924 is related to the handling of Feishu reaction events, where chat_type may be omitted, leading to misclassification.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203