PT-2026-99214 · Openclaw · Openclaw
CVE-2026-100578
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.7.1
Description
In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, the software fails to restrict owner-only infrastructure tools exposed through the 'chat.send' endpoint. A write-scoped non-owner caller can initiate a chat turn where the tool inventory includes the
gateway and cron tools. This allows the agent to perform owner-only configuration or scheduling operations, which may result in persistent state changes. The actual impact depends on the tools selected by the model and the caller's ability to guide the turn.Recommendations
Update to version 2026.7.1.
Restrict 'chat.send' to administrators in identity-bearing deployments.
Remove
gateway and cron from affected agent tool policies.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw