Authorization Bypass Vulnerability in OpenClaw npm Package
CVE-2026-100578

7.2HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100578?

The OpenClaw npm package prior to version 2026.7.1 contains an authorization bypass vulnerability that allows non-owner callers to access owner-restricted infrastructure tools via the chat.send endpoint. This vulnerability can enable a non-owner to initiate a chat turn that accesses sensitive tools, potentially leading to unauthorized configuration changes or scheduling operations. The impact may vary based on the capabilities of the tools selected and the caller's influence over the chat interactions. To mitigate this issue, it is recommended that chat.send access be restricted to administrators in identity-bearing deployments and that tools like gateway and cron be removed from the policies of affected agents.

Affected Version(s)

OpenClaw 0 < 2026.7.1

OpenClaw 2026.7.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.