{"id":"CVE-2026-27484","aliases":["GHSA-wh94-p5m6-mr7j"],"url":"https://o3.security/vulnerability/CVE-2026-27484","summary":"OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows","details":"OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, instead of trusted runtime sender context. In setups where Discord moderation actions are enabled and the bot has the necessary guild permissions, a non-admin user can request moderation actions by spoofing sender identity fields. This issue has been fixed in version 2026.2.18.","published":"2026-02-21T09:21:16.568Z","modified":"2026-08-07T11:50:49.677614822Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.18"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/775816035ecc6bb243843f8000c9a58ff609e32d","label":"openclaw/openclaw@7758160"},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/releases/tag/v2026.2.19"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27484.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-wh94-p5m6-mr7j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27484"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/775816035ecc6bb243843f8000c9a58ff609e32d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:49.677614822Z"}}