CVE-2026-34507: OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and allowFrom Checks
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin commands from unauthorized senders or contexts to execute restricted behavior that policy should have blocked.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.4.29
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34507?
CVE-2026-34507 has a low severity rating of 2.3.
How do I fix CVE-2026-34507?
To fix CVE-2026-34507, update OpenClaw to version 2026.4.29 or later.
What type of vulnerability is CVE-2026-34507?
CVE-2026-34507 is a policy bypass vulnerability in QQBot admin commands.
Who is affected by CVE-2026-34507?
Authenticated senders using OpenClaw before version 2026.4.29 are affected by CVE-2026-34507.
What can attackers do with CVE-2026-34507?
Attackers can exploit CVE-2026-34507 to execute restricted admin commands from unauthorized senders.