PT-2026-99229 · Openclaw · Openclaw

·

CVE-2026-100593

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions openclaw versions prior to 2026.7.1
Description The software fails to enforce the owner-only requirement for persistent policy changes via the /activation endpoint in group channels. This allows an authorized sender who is not the owner to modify whether the agent requires mention-based activation. Such an action can lead to the agent responding more broadly to group traffic or suppressing expected activation behavior.
Recommendations Update to version 2026.7.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100593
GHSA-Q9J5-4XR6-XQQW

Affected Products

Openclaw