CVE-2026-32035 MEDIUM

CVE-2026-32035: OpenClaw < 2026.3.2 - Missing Owner Flag Validation in Discord Voice Transcript Handler

Vendor Openclaw
Product OpenClaw
Weakness CWE-863 · Incorrect authorization
Published March 19, 2026
Last update March 20, 2026

CVSS base score

5.8/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag to default to true. Non-owner voice participants can exploit this omission to access owner-only tools including gateway and cron functionality in mixed-trust channels.

Key dates

02Disclosure timeline

March 19, 2026 CVE published
March 20, 2026 Record updated