PT-2026-99215 · Openclaw · Openclaw
CVE-2026-100579
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.7.1
Description
The software incorrectly trusts requester provenance in
message.action. In identity-bearing Gateway deployments, which are authentication modes that honor caller identity and narrower operator scopes, a write-scoped caller can provide another sender's identifier to the channel authorization checks. This allows the caller to invoke a channel action using a spoofed requester identity, enabling access to operations that the channel adapter would normally deny to the actual caller. The impact varies based on the enabled channel, the action performed, and the permissions of the target account.Recommendations
Update to version 2026.7.1.
Restrict
message.action to administrators.
Disable sensitive channel actions that rely on requester identity.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw