Authentication Bypass in OpenClaw Slack by OpenClaw
CVE-2026-100575
8.7HIGH
What is CVE-2026-100575?
OpenClaw Slack versions prior to 2026.8.1 are vulnerable to an authentication bypass issue in multi-person direct messages. The vulnerability arises due to inadequate enforcement of sender allowlists, enabling unauthorized participants to interact with Slack agents. As a result, these disallowed participants can trigger agents and gain access to tools and data that were only meant to be available to authorized users, circumventing established sender policies.
Affected Version(s)
slack 0 < 2026.8.1
slack 2026.8.1
