PT-2026-99228 · Openclaw · Openclaw

·

CVE-2026-100592

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.10 through 2026.7.0
Description Persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue the '/dreaming on' and '/dreaming off' commands to enable or disable the Gateway's Memory Core dreaming behavior. This allows an attacker to disable background memory processing or re-enable durable memory promotion against the owner's expectations. The impact on confidentiality, integrity, and availability depends on the stored conversation material and subsequent memory use. Read-only status and help commands are not affected.
Recommendations Update to version 2026.7.1. Disable dreaming commands in external channels. Restrict channel command access to owners.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100592
GHSA-22V4-33M3-8P7M

Affected Products

Openclaw