PT-2026-99202 · Unknown · Openclaw Line

·

CVE-2026-100566

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw LINE versions prior to 2026.8.1
Description An access control issue exists where the group allowlist mode silently inherits values from the DM allowFrom variable when groupAllowFrom is not explicitly configured. This allows attackers who are members of a group to trigger the agent, bypassing intended group allowlist restrictions if the direct message access is broader than the intended group access.
Recommendations Update to version 2026.8.1 or later. Explicitly configure the groupAllowFrom variable to prevent the inheritance of DM access settings.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100566
GHSA-FGWG-C3WV-8F45

Affected Products

Openclaw Line