CVE-2026-100566: OpenClaw LINE before 2026.8.1 Access Control Inheritance

Published Sep 26, 2026
·
Updated

OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. Attackers with group participation can trigger the agent despite configured group allowlist restrictions when DM access is broader than intended group access.

Affected Software

1 affected component
OpenClaw LINE<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw LINE to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

OpenClaw LINE deployments before 2026.8.1 are affected when group allowlist mode is used and groupAllowFrom is not explicitly configured. The exposure is greatest where DM allowFrom permits identities that should not be allowed to trigger the agent in groups.

2

What does an attacker need to exploit it?

An attacker needs to participate in a group where the affected agent is present and have an identity permitted by the inherited DM allowFrom values. No authentication beyond that access is indicated.

3

Are group allowlist restrictions effective by default in the affected configuration?

No. If groupAllowFrom is omitted, group allowlist mode silently inherits the DM allowFrom values, which can make group access broader than the intended group-specific restriction.

4

What can be done before upgrading?

Explicitly configure groupAllowFrom with the intended permitted group identities rather than relying on inherited DM allowFrom values. Review DM allowFrom entries because those values may currently define effective group access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203