PT-2026-99226 · Openclaw · Openclaw

·

CVE-2026-100590

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.7.1
Description An authorization bypass exists in the /voice set endpoint. This allows senders from external channels who are not owners to persist Gateway voice configuration. Attackers with command access can modify the voice used by Talk responses for the configured provider, which compromises configuration integrity. This issue does not expose credentials or grant additional host capabilities.
Recommendations Update to version 2026.7.1 or later. As a temporary mitigation, restrict access to the /voice set command.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100590
GHSA-5J27-V2PW-CJ9M

Affected Products

Openclaw