Description
OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named accounts. Attackers can exploit this trust propagation to bypass authentication controls and gain unauthorized access to named accounts.
Problem types
CWE-372: Incomplete Internal State Distinction
Product status
Any version before 2026.3.31
2026.3.31 (semver)
Credits
smaeljaish771
KeenSecurityLab
References
github.com/...enclaw/security/advisories/GHSA-f693-58pc-2gfr (GitHub Security Advisory (GHSA-f693-58pc-2gfr))
github.com/...ommit/d8c68c8d4265ea6fa5e8c5e056534c351bddef37 (Patch Commit)
www.vulncheck.com/...via-telegram-legacy-allowfrom-migration (VulnCheck Advisory: OpenClaw < 2026.3.31 - Authentication Boundary Bypass via Telegram Legacy allowFrom Migration)