
Cloud Vulnerability DB
A community-led vulnerabilities database
OpenClaw deployments before 2026.4.21 could treat a non-owner sender as authorized for owner-enforced slash commands when all of the following were true:
commands.enforceOwnerForCommands: true;allowFrom: ["*"];commands.ownerAllowFrom was configured.
In that state, src/auto-reply/command-auth.ts reused the channel inbound wildcard as part of the command-owner decision. A sender who was not the owner could therefore pass the owner-command gate for commands such as /send, /config, or /debug on the affected channel.
The issue is limited to the command-owner authorization axis. It does not by itself grant owner-only tool access, host/sandbox access, or gateway administrator scope.openclaw on npm<= 2026.4.202026.4.21
The latest public release, 2026.4.21, contains the fix.The fix requires a concrete owner identity or internal operator-admin scope when a plugin enforces owner-only commands. Wildcard channel allowFrom no longer implies wildcard command ownership.
Fix commits:
2aa93d44a1b2c7058c371f261fda2b5d4de4a882 on main995febb7b1e811ff6a1df5b18c22de94103f4c9f in the 2026.4.21 release lineUpgrade to openclaw@2026.4.21 or later. Before upgrading, avoid wildcard/open-DM sender policy on owner-enforced channels, or configure commands.ownerAllowFrom to the intended owner identities.
OpenClaw thanks @zsxsoft for reporting.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."