In authenticated non-owner DM sessions, a narrow tool-invocation path could reach broader-than-intended owner-only gateway actions.
This requires an authenticated non-owner sender in a DM session and a specific tool invocation path. No unauthenticated access is involved, and this does not provide direct code execution by itself.
openclaw (npm)<= 2026.2.17 (latest published npm version as of February 19, 2026)2026.2.19cron, gateway, whatsapp_login) and removed duplicated per-tool owner checks.a40c10d3e24568b1e2947c104484be74bf66b8d22777d8ad91ef1e8a7c6f5b4b18f8507be7d029143d7ad1cfca4daaa84cd553e843e0e08fa6201349OpenClaw thanks @Adam55A-code for reporting.
{
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": null,
"cwe_ids": [
"CWE-269",
"CWE-863"
],
"github_reviewed_at": "2026-03-03T21:36:33Z"
}