Authentication Bypass in OpenClaw Agent Gateway by Example Company
CVE-2026-100592

5.3MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100592?

The OpenClaw agent gateway, distributed through npm, is affected by an authentication bypass vulnerability in versions 2026.4.10 to 2026.7.0. This issue stems from persistent memory dreaming mutations that fail to enforce owner permission checks. As a result, any authorized external-channel sender, although not the owner, can issue commands to manipulate the Gateway's Memory Core. This allows for the unauthorized enabling or disabling of the Gateway's dreaming functionality, leading to potential risks regarding the confidentiality, integrity, and availability of stored conversations. Users are advised to upgrade to version 2026.7.1 for protection or limit channel command access to owners as a workaround.

Affected Version(s)

OpenClaw 2026.4.10 < 2026.7.1

OpenClaw 2026.7.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
.