OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actions outside operator configuration.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | 0 |
Updated affected versions to include 2026.5.11, changed severity to HIGH, and marked the vulnerability as actively exploited.
Initial creation