CVE-2026-33578
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group a
CVSS
4.3
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Mar 31, 2026 · Last modified: Jul 24, 2026 · CWE-863
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots despite configured allowlist restrictions.
- github.comhttps://github.com/openclaw/openclaw/commit/e64a881ae0fb8af18e451163f4c2d611d60cc8e4
- github.comhttps://github.com/openclaw/openclaw/security/advisories/GHSA-63mg-xp9j-jfcm
- www.vulncheck.comhttps://www.vulncheck.com/advisories/openclaw-sender-policy-allowlist-bypass-via-policy-downgrade-in-google-chat-and-zalouser-extensions
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-870758.1 HIG—
———Tanium addressed an improper access controls vulnerability in Comply.5hCVE-2026-870464.3 MED—
———Tanium addressed an improper access controls vulnerability in Comply.5hCVE-2026-148924.3 MED—
———Tanium addressed an improper access controls vulnerability in Tanium Server.5hCVE-2026-87652——
———Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)7hCVE-2026-87651——
———Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)7hCVE-2026-87644——
———Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)7h