Channel Read Allowlist Bypass in OpenClaw Plugins by OpenClaw
CVE-2026-100582

7.1HIGH

Key Information:

Vendor

Openclaw

Vendor
CVE Published:
26 September 2026

What is CVE-2026-100582?

The OpenClaw channel plugins, including @openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat, prior to version 2026.8.1, fail to enforce the configured channel read allowlist for caller-supplied explicit read targets. This can allow lower-trust senders or unauthorized agents to access and retrieve content or metadata from channels that should be restricted by the operator's read policy. The severity of this issue is influenced by the permissions of the bot account in use. A patch has been provided in version 2026.8.1.

Affected Version(s)

feishu 0 < 2026.8.1

googlechat 0 < 2026.8.1

matrix 0 < 2026.8.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

qc9c
.