PT-2026-99218 · Unknown · @Openclaw/Matrix+3
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@openclaw/msteams versions prior to 2026.8.1
@openclaw/feishu versions prior to 2026.8.1
@openclaw/matrix versions prior to 2026.8.1
@openclaw/googlechat versions prior to 2026.8.1
Description
Channel plugins fail to enforce the configured channel read allowlist when processing caller-supplied explicit read targets. This occurs during read actions for messages, reactions, pins, members, and related metadata. Consequently, a lower-trust sender or a steered agent with access to a channel read action can retrieve content or metadata from channels or rooms that the operator's read policy intended to exclude. The actual impact is determined by the permissions assigned to the connected bot account.
Recommendations
Update @openclaw/msteams to version 2026.8.1 or later.
Update @openclaw/feishu to version 2026.8.1 or later.
Update @openclaw/matrix to version 2026.8.1 or later.
Update @openclaw/googlechat to version 2026.8.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw/Feishu
@Openclaw/Googlechat
@Openclaw/Matrix
Openclaw Ms Teams