Delivery queue recovery could lose group tool-policy context for media replay.
openclaw>= 2026.4.10 < 2026.4.14>= 2026.4.14Recovered queued outbound media could be replayed without the original session context needed to enforce group tool policy, weakening channel media restrictions after restart/recovery.
The fix persists and replays the relevant session context with delivery queue entries so recovered media dispatch goes through the same policy checks.
The issue was fixed in #66025. The first stable tag containing the fix is v2026.4.14, and openclaw@2026.4.14 includes the fix.
48aae82bbc19ba8b0741e61a08063eb0d1df464eUsers should upgrade to openclaw 2026.4.14 or newer. The latest npm release, 2026.4.14, already includes the fix.
Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-17T21:50:55Z",
"nvd_published_at": null,
"severity": "LOW"
}