Authentication Bypass in OpenClaw Slack by OpenClaw
CVE-2026-100575

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100575?

OpenClaw Slack versions prior to 2026.8.1 are vulnerable to an authentication bypass issue in multi-person direct messages. The vulnerability arises due to inadequate enforcement of sender allowlists, enabling unauthorized participants to interact with Slack agents. As a result, these disallowed participants can trigger agents and gain access to tools and data that were only meant to be available to authorized users, circumventing established sender policies.

Affected Version(s)

slack 0 < 2026.8.1

slack 2026.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.