CVE-2026-100593
Last modified
CVE-2026-100593 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires mention-based activation, causing the agent to respond more broadly in the group (exposing its responses to additional group traffic) or suppressing expected activation behavior until an owner restores the intended setting.
Description
OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel sender can change whether the agent requires mention-based activation, causing the agent to respond more broadly in the group (exposing its responses to additional group traffic) or suppressing expected activation behavior until an owner restores the intended setting. The issue is fixed in version 2026.7.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenClaw | OpenClaw | < 2026.7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100593?
How severe is CVE-2026-100593?
How do I fix CVE-2026-100593?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100588OpenClaw (npm package 'openclaw') before 2026.7.1 does not e…8.3
- CVE-2026-100589OpenClaw versions before 2026.7.1 contain a sandbox bypass v…8.3
- CVE-2026-10059A flaw was found in the Multicluster Engine for Kubernetes C…9.1
- CVE-2026-100590OpenClaw before 2026.7.1 contains an authorization bypass vu…4.3
- CVE-2026-100591OpenClaw is an npm-distributed agent gateway. In versions be…6.3
- CVE-2026-100592OpenClaw is an agent gateway distributed via npm. In version…6.3
- CVE-2026-100594OpenClaw versions before 2026.7.1 contain an authorization b…6.5
- CVE-2026-100595OpenClaw versions before 2026.7.1 contain an authorization b…6.5
- CVE-2026-100596OpenClaw versions before 2026.7.1 fail to properly authorize…8.8
- CVE-2026-100597OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnera…7.8
- CVE-2026-100598OpenClaw (npm package openclaw) before 2026.7.1 incorrectly …7.1
- CVE-2026-100599OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply th…8.8
Are you affected by CVE-2026-100593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
