CVE-2026-100556
Received Received - Intake

Incorrect Authorization in OpenClaw npm Package Allows Session Reset

Vulnerability report for CVE-2026-100556, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the /new <model> command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability. It does not allow adding a new provider or host command execution. The issue is fixed in version 2026.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw From 2026.5.2 (inc) to 2026.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the openclaw npm package versions between 2026.5.2 and 2026.8.1. It allows a WhatsApp group sender who can send ordinary messages but is denied by command authorization to use the /new <model> command to reset the shared group session and override provider and model settings. This bypasses intended authorization restrictions without adding new providers or enabling host command execution.

Detection Guidance

To detect this vulnerability, check for unauthorized use of the /new <model> command in WhatsApp group sessions. Monitor logs for session resets or unexpected provider/model changes in OpenClaw versions between 2026.5.2 and 2026.8.1. Verify command authorization policies and group admission settings for inconsistencies.

Impact Analysis

The impact includes potential changes to provider routing, cost, data flow, or availability in WhatsApp group sessions. Attackers could alter settings for subsequent interactions, though they cannot add new providers or execute host commands. The vulnerability requires low privileges and no user interaction, making it exploitable with minimal effort.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized changes to data processing flows. Specifically, it enables a denied group member to reset shared sessions and override provider/model settings, which may alter data routing, storage, or processing paths. Such unauthorized modifications could violate data integrity, access control, or audit requirements mandated by these regulations.

Mitigation Strategies

Upgrade OpenClaw to version 2026.8.1 or later. Ensure command authorization policies (commands.allowFrom) align with WhatsApp group admission settings. Reset affected group sessions after unauthorized /new command attempts to prevent persistent overrides.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100556. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart