CVE-2026-44110: Openclaw

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can execute room control commands without being in configured allowlists by posting in bot rooms, potentially enabling privileged OpenClaw behavior.

Affected products

  • Openclaw Openclaw: before 2026.4.15 (fixed in 2026.4.15)

Published 2026-05-06. Last modified 2026-06-17.