Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
7.6
CVE-2026-100579PATCHED
openclaw · openclaw

OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester

Description

OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bearing Gateway deployments (authentication modes that honor caller identity and narrower operator scopes), a write-scoped caller can supply another sender's identifier to the channel authorization checks and invoke a channel action under that spoofed requester identity, reaching operations the channel adapter would have denied to the real caller. Practical impact depends on the enabled channel, the action, and the target account's permissions. Shared-secret token and password callers are full trusted operators under OpenClaw's security model and are out of scope. The issue is fixed in 2026.7.1; as a workaround, restrict message.action to administrators and disable sensitive channel actions that rely on requester identity.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-4wvr-f35r-f8w4(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-authentication-bypass-via-spoofed-requester(third-party-advisory)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-100579 | OpenClaw up to 2026.7.0 privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.7.1
CWECWE-639
PublishedSep 26, 2026
Last enriched1d ago
Trending Score22
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-100604EXP
ClawHub Authentication Bypass via Former Publisher Skill Control
Trending: 47
HIGHCVE-2026-100599EXP
OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
Trending: 36
HIGHCVE-2026-100589
OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
Trending: 23
HIGHCVE-2026-100597
OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
Trending: 23
HIGHCVE-2026-100596
OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 26, 2026
Discovered by ZDM
Sep 26, 2026
Patch Available
Sep 26, 2026