PT-2026-99218 · Unknown · @Openclaw/Matrix+3

·

CVE-2026-100582

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @openclaw/msteams versions prior to 2026.8.1 @openclaw/feishu versions prior to 2026.8.1 @openclaw/matrix versions prior to 2026.8.1 @openclaw/googlechat versions prior to 2026.8.1
Description Channel plugins fail to enforce the configured channel read allowlist when processing caller-supplied explicit read targets. This occurs during read actions for messages, reactions, pins, members, and related metadata. Consequently, a lower-trust sender or a steered agent with access to a channel read action can retrieve content or metadata from channels or rooms that the operator's read policy intended to exclude. The actual impact is determined by the permissions assigned to the connected bot account.
Recommendations Update @openclaw/msteams to version 2026.8.1 or later. Update @openclaw/feishu to version 2026.8.1 or later. Update @openclaw/matrix to version 2026.8.1 or later. Update @openclaw/googlechat to version 2026.8.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100582
GHSA-G7FW-3GJP-G5HF

Affected Products

Openclaw/Feishu
@Openclaw/Googlechat
@Openclaw/Matrix
Openclaw Ms Teams