Unknown · @Openclaw/Matrix · CVE-2026-100582
**Name of the Vulnerable Software and Affected Versions**
@openclaw/msteams versions prior to 2026.8.1
@openclaw/feishu versions prior to 2026.8.1
@openclaw/matrix versions prior to 2026.8.1
@openclaw/googlechat versions prior to 2026.8.1
**Description**
Channel plugins fail to enforce the configured channel read allowlist when processing caller-supplied explicit read targets. This occurs during read actions for messages, reactions, pins, members, and related metadata. Consequently, a lower-trust sender or a steered agent with access to a channel read action can retrieve content or metadata from channels or rooms that the operator's read policy intended to exclude. The actual impact is determined by the permissions assigned to the connected bot account.
**Recommendations**
Update @openclaw/msteams to version 2026.8.1 or later.
Update @openclaw/feishu to version 2026.8.1 or later.
Update @openclaw/matrix to version 2026.8.1 or later.
Update @openclaw/googlechat to version 2026.8.1 or later.