OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100575

HIGH · CVSS 8.8 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

OpenClaw Slack versions prior to 2026.8.1 are vulnerable due to inadequate enforcement of sender allowlists in multi-person direct messages, allowing unauthorized participants to trigger Slack agents. This flaw can lead to unauthorized access to tools and data associated with these agents, posing a significant security risk. Organizations using affected versions should prioritize updating to mitigate potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100575
Severity
HIGH
CVSS
8.8
EPSS
0.26%

Original NVD Description

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.