Authentication Bypass in OpenClaw Agent Gateway by Example Company
CVE-2026-100592
What is CVE-2026-100592?
The OpenClaw agent gateway, distributed through npm, is affected by an authentication bypass vulnerability in versions 2026.4.10 to 2026.7.0. This issue stems from persistent memory dreaming mutations that fail to enforce owner permission checks. As a result, any authorized external-channel sender, although not the owner, can issue commands to manipulate the Gateway's Memory Core. This allows for the unauthorized enabling or disabling of the Gateway's dreaming functionality, leading to potential risks regarding the confidentiality, integrity, and availability of stored conversations. Users are advised to upgrade to version 2026.7.1 for protection or limit channel command access to owners as a workaround.
Affected Version(s)
OpenClaw 2026.4.10 < 2026.7.1
OpenClaw 2026.7.1
