CVE-2026-100590: OpenClaw before 2026.7.1 Authorization Bypass via voice set
OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured provider, affecting configuration integrity without exposing credentials or granting additional host capabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.7.1
Event History
Frequently Asked Questions
Who can exploit this issue?
Non-owner senders on external channels can exploit it if they have access to issue the /voice set command. No user interaction is required.
What is the impact of successful exploitation?
An attacker can persistently change the Gateway voice configuration used for Talk responses by the configured provider. The issue affects configuration integrity; it does not expose credentials or grant additional host capabilities.
Which versions are affected?
OpenClaw versions before 2026.7.1 are affected.