OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100578

HIGH · CVSS 7.6 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The OpenClaw npm package prior to version 2026.7.1 is vulnerable due to insufficient restrictions on the chat.send endpoint, allowing non-owner users to invoke owner-only tools like `gateway` and `cron`. This could lead to unauthorized configuration changes and scheduling operations, posing a significant risk in environments where caller identity is honored. Organizations using OpenClaw, particularly those with Gateway deployments, should prioritize upgrading to version 2026.7.1 or implementing workarounds to restrict access to these tools.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100578
Severity
HIGH
CVSS
7.6
EPSS
0.23%

Original NVD Description

OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.send endpoint. In Gateway deployments using authentication modes that honor caller identity and narrower operator scopes, a write-scoped non-owner caller can start a chat turn whose tool inventory includes the `gateway` and `cron` tools, causing the agent to invoke owner-only configuration or scheduling operations, including persistent state changes. Practical impact depends on the tools selected by the model and the caller's ability to steer the turn. Shared-secret token and password callers are treated as fully trusted operators under OpenClaw's security model and are outside the scope of this issue. The issue is fixed in 2026.7.1; as a workaround, restrict chat.send to administrators in identity-bearing deployments and remove `gateway` and `cron` from affected agent tool policies.