Authentication Bypass in OpenClaw by Spoofed Requester Identity
CVE-2026-100579
7.2HIGH
What is CVE-2026-100579?
The OpenClaw npm package contains a vulnerability that allows an attacker to exploit trust in requester provenance in certain message actions. In environments where identity is critical, a write-scoped caller can impersonate another user's identity and perform actions on a channel that would normally be restricted. This flaw may lead to unauthorized access to sensitive operations, depending on the specific channel configuration, action taken, and the permissions associated with the target account. The issue has been resolved in version 2026.7.1, and users are advised to apply the latest updates and consider restricting actions to administrators to mitigate potential risks.
Affected Version(s)
OpenClaw 0 < 2026.7.1
OpenClaw 2026.7.1
