CVE-2026-44110

8.8

OpenClaw · OpenClaw

OpenClaw before 2026.4.15 has an authorization bypass vulnerability in Matrix room control commands via DM pairing store.

Executive summary

An authorization bypass vulnerability in OpenClaw allows authenticated attackers with direct message pairing to execute unauthorized room control commands, risking total system compromise.

Vulnerability

This is an incorrect authorization flaw (CWE-863) residing in the Matrix room control command authorization mechanism, which improperly trusts direct message pairing store entries. The attacker requires low privileges through a direct message paired sender ID.

Business impact

A successful exploitation of this vulnerability permits attackers to bypass configured allowlists and execute privileged room control commands within bot rooms. Given the high CVSS score of 8.8, this risk translates into potential total confidentiality, integrity, and availability impact, threatening critical business communications and automated operational infrastructure.

Remediation

Immediate Action: Update OpenClaw to version 2026.4.15 or later to resolve the authorization logic flaw.

Proactive Monitoring: Monitor access and chat logs for unusual command executions within bot rooms originating from unexpected direct message participants.

Compensating Controls: Restrict bot room access and review Matrix integration permissions to limit potential exposure until updates are applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a severe risk to environments utilizing OpenClaw and Matrix integrations due to the potential for unauthorized command execution. Administrators should apply the vendor security update immediately to version 2026.4.15 or later to neutralize the authorization bypass vector and secure affected systems.

More OpenClaw CVEs

Sources

Originally found and disclosed by Nathan (@nexrin), KeenSecurityLab, qclawer, per the CVE Program record.