CVE-2026-32924: OpenClaw < 2026.3.12 - Authorization Bypass via Misclassified Reaction Events in Feishu
OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chattype are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAllowFrom and requireMention protections in group chat reaction-derived events.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32924?
CVE-2026-32924 has a high severity rating due to its potential to allow unauthorized access to user conversations.
How do I fix CVE-2026-32924?
To fix CVE-2026-32924, upgrade to OpenClaw version 2026.3.12 or later, which addresses the authorization bypass issue.
What software is affected by CVE-2026-32924?
CVE-2026-32924 affects OpenClaw versions prior to 2026.3.12.
What exploit can attackers perform using CVE-2026-32924?
Attackers can exploit CVE-2026-32924 to bypass authorization and access p2p conversations misclassified as group chats.
Is CVE-2026-32924 related to any specific features of OpenClaw?
CVE-2026-32924 is related to the handling of Feishu reaction events, where chat_type may be omitted, leading to misclassification.