PT-2026-99214 · Openclaw · Openclaw

CVE-2026-100578

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.7.1
Description In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, the software fails to restrict owner-only infrastructure tools exposed through the 'chat.send' endpoint. A write-scoped non-owner caller can initiate a chat turn where the tool inventory includes the gateway and cron tools. This allows the agent to perform owner-only configuration or scheduling operations, which may result in persistent state changes. The actual impact depends on the tools selected by the model and the caller's ability to guide the turn.
Recommendations Update to version 2026.7.1. Restrict 'chat.send' to administrators in identity-bearing deployments. Remove gateway and cron from affected agent tool policies.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100578
GHSA-QW7M-H363-33QW

Affected Products

Openclaw