CVE-2026-44993: OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct message conversations that should have been blocked by restrictive policies.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44993?
CVE-2026-44993 has been classified as a significant vulnerability due to its potential to bypass direct message policy enforcement.
How do I fix CVE-2026-44993?
To fix CVE-2026-44993, upgrade OpenClaw to version 2026.4.20 or later.
What type of vulnerability is CVE-2026-44993?
CVE-2026-44993 is a direct message misclassification vulnerability in Feishu card actions.
What impacts can CVE-2026-44993 have?
CVE-2026-44993 allows attackers to misclassify direct messages as group conversations, bypassing dmPolicy enforcement.
Which versions of OpenClaw are affected by CVE-2026-44993?
Versions of OpenClaw prior to 2026.4.20 are affected by CVE-2026-44993.