Unknown · Openclaw Line · CVE-2026-100566
**Name of the Vulnerable Software and Affected Versions**
OpenClaw LINE versions prior to 2026.8.1
**Description**
An access control issue exists where the group allowlist mode silently inherits values from the DM `allowFrom` variable when `groupAllowFrom` is not explicitly configured. This allows attackers who are members of a group to trigger the agent, bypassing intended group allowlist restrictions if the direct message access is broader than the intended group access.
**Recommendations**
Update to version 2026.8.1 or later.
Explicitly configure the `groupAllowFrom` variable to prevent the inheritance of DM access settings.