PT-2026-99229 · Openclaw · Openclaw
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
openclaw versions prior to 2026.7.1
Description
The software fails to enforce the owner-only requirement for persistent policy changes via the
/activation endpoint in group channels. This allows an authorized sender who is not the owner to modify whether the agent requires mention-based activation. Such an action can lead to the agent responding more broadly to group traffic or suppressing expected activation behavior.Recommendations
Update to version 2026.7.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw