CyberRota Analysis
AI-GeneratedVersions 2026.6.6 and earlier of OpenClaw @openclaw/feishu are vulnerable due to an incorrect authorization flaw that allows lower-trust users to bypass account-specific disablement settings, potentially leading to unauthorized actions. This vulnerability poses a significant risk to organizations relying on these versions for secure permission management. Users of the affected software should prioritize upgrading to version 2026.6.9 to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.
Related CVEs
Other vulnerabilities affecting the same vendor(s)