CVE-2026-100583
Received Received - Intake

Authorization Bypass in OpenClaw Discord Guild Metadata

Vulnerability report for CVE-2026-100583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels outside the operator's allowlist.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw discord to 2026.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in OpenClaw Discord versions before 2026.7.1. It allows lower-privileged users to access guild metadata that should be restricted by channel allowlists. Attackers can bypass configured read-target policies to retrieve metadata from servers or channels outside the operator's specified allowlist.

Detection Guidance

This vulnerability involves an authorization bypass in OpenClaw Discord versions before 2026.7.1. To detect it, check the installed version of OpenClaw Discord using commands like 'pip show openclaw-discord' or 'openclaw-discord --version'. If the version is below 2026.7.1, the system is vulnerable.

Impact Analysis

The impact depends on the bot account's platform permissions and accessible servers. Attackers with access to Discord read actions could retrieve sensitive guild metadata that was meant to be restricted. This could lead to unauthorized access to server or channel information.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to guild metadata, which may include sensitive user or organizational data. If such data is exposed outside intended allowlists, it may violate data protection requirements for access controls and confidentiality.

Mitigation Strategies

Upgrade OpenClaw Discord to version 2026.7.1 or later to patch the authorization bypass vulnerability. Alternatively, disable Discord guild metadata actions until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart