CVE-2026-100593: OpenClaw before 2026.7.1 Authentication Bypass via activation

Published Sep 26, 2026
·
Updated

OpenClaw (npm package openclaw) before 2026.7.1 does not enforce the documented owner-only requirement for persistent /activation policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires mention-based activation, causing the agent to respond more broadly in the group (exposing its responses to additional group traffic) or suppressing expected activation behavior until an owner restores the intended setting. The issue is fixed in version 2026.7.1.

Affected Software

1 affected component
npm/openclaw<2026.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openclaw to a version that resolves this vulnerability.

    Fixed in 2026.7.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authorized non-owner sender in a group channel can exploit it. The attacker must be able to send messages in the affected channel; unauthenticated external attackers are not described as able to change the policy.

2

Which deployments are affected?

Deployments using the npm package openclaw before version 2026.7.1 are affected where persistent /activation policy changes can be made in group channels. The issue concerns the owner-only authorization check for those changes.

3

What can an attacker change through the bypass?

They can change whether the agent requires mention-based activation in the group. This can make the agent respond to broader group traffic or suppress the expected activation behavior until an owner restores the setting.

4

What should teams do if they cannot update immediately?

Limit group-channel membership to trusted authorized senders and have an owner monitor and restore the intended /activation setting. Updating to version 2026.7.1 is the stated fix.

5

How can an owner check for potential impact?

Review the current persistent /activation policy in each group channel and verify that it matches the owner’s intended mention-based activation behavior. Unexpected broader responses or suppressed activation behavior may indicate the setting was changed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203