CVE-2026-100540
Received Received - Intake

Path Traversal in OpenClaw Feishu Extension

Vulnerability report for CVE-2026-100540, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw feishu to 2026.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw Feishu before version 2026.8.1 fails to check if a configured default account is disabled before using it for model tool operations. In setups with multiple accounts, a disabled default account may still retain credentials, allowing attackers to exploit this to read or modify Feishu resources through a revoked identity.

Detection Guidance

Check OpenClaw Feishu version with npm list @openclaw/feishu. If version is below 2026.8.1, the system is vulnerable. Inspect Feishu account configurations for disabled default accounts with retained credentials.

Impact Analysis

If you use OpenClaw Feishu with multiple accounts and have a disabled default account, attackers could exploit this to access your Feishu resources using the disabled account's credentials. This could lead to unauthorized reading or modification of sensitive data depending on the disabled account's permissions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements like GDPR or HIPAA which mandate strict access controls and data protection. Unauthorized access may result in data breaches, leading to legal penalties or reputational damage.

Mitigation Strategies

Upgrade to OpenClaw Feishu version 2026.8.1 or later. Remove credentials from disabled accounts. Change defaultAccount to an enabled eligible account. Restart OpenClaw after disabling a Feishu identity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart