CVE Watchtower


← Back to CVE List

CVE-2026-32906NVD

Vulnerability Summary

OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actions outside operator configuration.
Severity Level
MEDIUM(4.3)
Published Date
May 29, 2026
Last Modified
Jun 2, 2026
Exploitation Status
UNKNOWN
Root Weakness (CWE)
N/A
EPSS Score (30-Day)
0.03%Probability
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone