PT-2026-99190 · Openclaw · Openclaw

·

CVE-2026-100553

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.6.9 through 2026.8.0
Description The Feishu unpin feature fails to declare the native chatId parameter as a delivery target. This allows unpin requests to bypass the shared same-provider cross-context target check. When the tools.message.crossContext.allowWithinProvider setting is disabled, an authenticated sender can remove a pin from a different Feishu group that both the sender and the configured account have permission to access. This bypasses the cross-context message mutation policy, although Feishu membership and group authorization remain in effect.
Recommendations Update OpenClaw to version 2026.8.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100553
GHSA-H9JH-75J7-7HHX

Affected Products

Openclaw