PT-2026-99234 · Openclaw · Openclaw

·

CVE-2026-100598

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openclaw versions prior to 2026.7.1
Description The software incorrectly binds Signal approval reactions. When unrelated outbound messages and a pending approval exist in the same conversation, a reaction intended for a structured approval request may attach to ordinary outbound text. This can lead to an approver's reaction to unrelated text being interpreted as approving or denying a pending host action, depending on the request, conversation timing, and available process actions. This issue does not alter the authority of identified approvers.
Recommendations Update to version 2026.7.1.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100598
GHSA-R88X-R7JJ-F2CF

Affected Products

Openclaw