A vulnerability classified as critical has been found in OpenClaw up to 2026.4.28. The impacted element is an unknown function of the component QQBot Admin Command Handler. Performing a manipulation results in incorrect authorization. This vulnerability is known as CVE-2026-34507. Remote exploitation of the attack is possible.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | openclaw | 0, 2026.4.28 |
Updated severity to CRITICAL, added affected version 2026.4.28, and noted that the vulnerability is actively exploited.
Initial creation