PT-2026-99215 · Openclaw · Openclaw

CVE-2026-100579

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.7.1
Description The software incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments, which are authentication modes that honor caller identity and narrower operator scopes, a write-scoped caller can provide another sender's identifier to the channel authorization checks. This allows the caller to invoke a channel action using a spoofed requester identity, enabling access to operations that the channel adapter would normally deny to the actual caller. The impact varies based on the enabled channel, the action performed, and the permissions of the target account.
Recommendations Update to version 2026.7.1. Restrict message.action to administrators. Disable sensitive channel actions that rely on requester identity.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100579
GHSA-4WVR-F35R-F8W4

Affected Products

Openclaw