{"id":"CVE-2026-33578","title":"OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy","summary":"OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-863"],"vendor":"openclaw","product":"openclaw","affected":["openclaw < 2026.3.28"],"patched":["openclaw 2026.3.28"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33578","references":[{"url":"https://github.com/openclaw/openclaw/commit/e64a881ae0fb8af18e451163f4c2d611d60cc8e4","label":"disclosure@vulncheck.com"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-63mg-xp9j-jfcm","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-sender-policy-allowlist-bypass-via-policy-downgrade-in-google-chat-and-zalouser-extensions","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00307,"epssPercentile":0.20834,"ingestedAt":"2026-07-24T21:39:13.118Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-04-01T03:55:25.603378Z"},"slug":"CVE-2026-33578","body":"## Overview\n\nOpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots despite configured allowlist restrictions.\n\n## Affected\n\n- `openclaw < 2026.3.28`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openclaw 2026.3.28`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}