PT-2026-99169 · Unknown · @Openclaw/Whatsapp
CVE-2026-100532
·
Published
2026-09-26
·
Updated
2026-09-30
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
@openclaw/whatsapp versions prior to 2026.8.1
Description
The software exposes the WhatsApp login tool through the generic
channel-tool path without preserving the originating sender's owner status, failing to enforce the owner-only tool boundary. A non-owner sender who can steer the tool may request a forced login and receive a new QR code for a configured account. This action disconnects the Gateway's WhatsApp account, resulting in a loss of availability. Full account relinking would further require the attacker to scan the provided QR code with another phone. This issue specifically impacts the owner-only tool boundary and not the WhatsApp transport authentication.Recommendations
Update to version 2026.8.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Openclaw/Whatsapp