Loading market data...
← Back to CVE feed

CVE-2026-33578

MEDIUM CVSS 4.3 View on NVD ↗

Description

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots despite configured allowlist restrictions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Mar 31, 2026 15:16 UTC Modified: Mar 31, 2026 18:16 UTC