Authorization Bypass in OpenClaw's Matrix Integration by OpenClaw
CVE-2026-100541

7.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100541?

The OpenClaw Matrix integration vulnerabilities arise from the normalization of user IDs during authorization, allowing distinct authenticated accounts to collide and share access rights. Specifically, the application incorrectly handles case and Unicode variations within Matrix user IDs, potentially permitting an attacker to exploit this flaw by controlling an account that can leverage the privileges of another user. This issue, which affects versions prior to 2026.8.1, has been addressed in the subsequent release to prevent such unauthorized access.

Affected Version(s)

matrix 2026.2.2 < 2026.8.1

matrix 2026.8.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.