Channel Read Allowlist Bypass in OpenClaw Plugins by OpenClaw
CVE-2026-100582
7.1HIGH
Key Information:
- Vendor
Openclaw
- Vendor
- CVE Published:
- 26 September 2026
What is CVE-2026-100582?
The OpenClaw channel plugins, including @openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat, prior to version 2026.8.1, fail to enforce the configured channel read allowlist for caller-supplied explicit read targets. This can allow lower-trust senders or unauthorized agents to access and retrieve content or metadata from channels that should be restricted by the operator's read policy. The severity of this issue is influenced by the permissions of the bot account in use. A patch has been provided in version 2026.8.1.
Affected Version(s)
feishu 0 < 2026.8.1
googlechat 0 < 2026.8.1
matrix 0 < 2026.8.1
