CVE-2026-100575: OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM

Published Sep 26, 2026
·
Updated

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.

Affected Software

1 affected component
OpenClaw Slack<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw Slack to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

OpenClaw Slack deployments before 2026.8.1 that use sender allowlists are exposed when agents can participate in multi-person Slack direct messages. The risk is highest where those agents have access to sensitive tools or data.

2

What does an attacker need to exploit it?

An attacker needs to be a disallowed participant in a multi-person direct message that includes the affected Slack agent. No user interaction is required, but the attacker must have the Slack access needed to participate in that group DM.

3

Are default configurations affected?

The issue specifically concerns configured sender allowlists. The provided information does not establish whether deployments without sender allowlists, or a particular default configuration, are affected.

4

What can be done if upgrading is not immediately possible?

Avoid placing affected agents in multi-person direct messages with untrusted or disallowed participants. Restrict agent access to sensitive tools and data until the deployment can be updated to 2026.8.1 or later.

5

How can I tell whether my deployment may already be affected?

Review whether an OpenClaw Slack version before 2026.8.1 is deployed, whether sender allowlists are configured, and whether agents have been included in group DMs containing disallowed participants. The provided information does not indicate specific logging artifacts or indicators of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203