Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-100575: OpenClaw Slack allows unauthorized access via group DM

CVE-2026-100575 · published 15 days ago
Summary

Older versions of OpenClaw Slack let people who aren’t supposed to be in a group direct message trick the system into acting as if they were authorized. This can give them access to tools and data that should be restricted. Upgrade to the latest version or apply the vendor’s recommended fix to restore proper access controls.

What to do
  • Update openclaw slack to version 2026.8.1 or later.
Affected software
VendorProductAffected versions
openclaw slack < 2026.8.1
Original advisory text
OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM
OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published26 Sep 2026
Updated9 Oct 2026
First seen26 Sep 2026
Sources
CVE-2026-100575 · MITRE
Track software like this
Free during beta