Authorization Vulnerability in OpenClaw NPM Package by OpenClaw
CVE-2026-100556

5.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100556?

The OpenClaw NPM package exhibits an authorization bypass vulnerability in its handling of WhatsApp group interactions. A group member, initially granted permission for basic messaging but restricted from executing commands, could exploit this flaw to utilize the /new command. This command enables unauthorized group members to reset the shared group session, thus overriding the specified provider and model settings. Consequently, this may alter routing, cost, data flow, or availability within the session, while it does not permit the addition of new providers or execute host commands. The issue has been resolved in version 2026.8.1.

Affected Version(s)

OpenClaw 2026.5.2 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andrewCantina
.