Authorization Bypass in OpenClaw Discord Affecting Guild Metadata Access
CVE-2026-100583
5.3MEDIUM
What is CVE-2026-100583?
OpenClaw Discord prior to version 2026.7.1 contains an authorization bypass vulnerability that enables low-trust users to access guild metadata through unauthorized read actions. This flaw allows attackers to circumvent configured read-target policies, resulting in potential exposure of sensitive guild information from channels not included in the operator’s allowlist.
Affected Version(s)
discord 0 < 2026.7.1
discord 2026.7.1
