PT-2026-99202 · Unknown · Openclaw Line
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw LINE versions prior to 2026.8.1
Description
An access control issue exists where the group allowlist mode silently inherits values from the DM
allowFrom variable when groupAllowFrom is not explicitly configured. This allows attackers who are members of a group to trigger the agent, bypassing intended group allowlist restrictions if the direct message access is broader than the intended group access.Recommendations
Update to version 2026.8.1 or later.
Explicitly configure the
groupAllowFrom variable to prevent the inheritance of DM access settings.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw Line