{"id":"CVE-2026-32067","aliases":["GHSA-vjp8-wprm-2jw9"],"url":"https://o3.security/vulnerability/CVE-2026-32067","summary":"OpenClaw < 2026.2.26 - Cross-Account Authorization Bypass in DM Pairing Store","details":"OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.","published":"2026-03-21T00:42:30.798Z","modified":"2026-08-17T03:55:01.630303738Z","cvss":null,"epss":{"score":0.00165,"percentile":0.06127,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.26"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/a0c5e28f3bf0cc0cd9311f9e9ec2ca0352550dcf","label":"openclaw/openclaw@a0c5e28"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32067.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-vjp8-wprm-2jw9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32067"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-cross-account-authorization-bypass-in-dm-pairing-store"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/a0c5e28f3bf0cc0cd9311f9e9ec2ca0352550dcf"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/bce643a0bd145d3e9cb55400af33bd1b85baeb02"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T03:55:01.630303738Z"}}