Authentication Bypass in OpenClaw by Spoofed Requester Identity
CVE-2026-100579

7.2HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100579?

The OpenClaw npm package contains a vulnerability that allows an attacker to exploit trust in requester provenance in certain message actions. In environments where identity is critical, a write-scoped caller can impersonate another user's identity and perform actions on a channel that would normally be restricted. This flaw may lead to unauthorized access to sensitive operations, depending on the specific channel configuration, action taken, and the permissions associated with the target account. The issue has been resolved in version 2026.7.1, and users are advised to apply the latest updates and consider restricting actions to administrators to mitigate potential risks.

Affected Version(s)

OpenClaw 0 < 2026.7.1

OpenClaw 2026.7.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.