CVE-2026-100593 Overview
CVE-2026-100593 affects the openclaw npm package in versions prior to 2026.7.1. The package fails to enforce its documented owner-only requirement for persistent /activation policy changes inside group channels. An authorized non-owner sender can modify whether the agent requires mention-based activation. This causes the agent to respond more broadly to group traffic or to suppress expected activation behavior until an owner restores the configured setting. The flaw is classified under CWE-862: Missing Authorization and is fixed in 2026.7.1.
Critical Impact
Any authorized channel sender can toggle the agent's activation policy, altering response scope across the group without owner consent.
Affected Products
- openclaw npm package versions prior to 2026.7.1
- OpenClaw agent deployments integrated into group channel environments
- Downstream applications bundling vulnerable openclaw releases
Discovery Timeline
- 2026-09-26 - CVE-2026-100593 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100593
Vulnerability Analysis
The vulnerability is a missing authorization check on the /activation command handler in group channels. OpenClaw documents the /activation policy as owner-only. The implementation does not validate the sender's role before persisting the change. Any user already authorized to send messages in the channel can issue the command. The change persists until an owner reverts it.
The practical result is a configuration drift primitive. By disabling mention-based activation, an attacker widens the agent's response surface so it reacts to additional group traffic. By enabling it unexpectedly, an attacker silences the agent until the owner notices. Both outcomes affect integrity and confidentiality of the agent's interaction model within the channel.
Root Cause
The root cause is an authorization gap in the /activation command path. The handler trusts the sender's existing channel-send permission as sufficient. It does not verify that the sender holds the owner role before applying a persistent configuration change. This matches the CWE-862 pattern of missing authorization on a state-changing operation.
Attack Vector
Exploitation requires network access to the group channel and a valid non-owner account with send privileges. No user interaction from the owner is required. The attacker submits the /activation command with the target policy value. The agent persists the setting and begins operating under the attacker-chosen activation mode. See the GitHub Security Advisory GHSA-q9j5-4xr6-xqqw and the VulnCheck advisory for additional context.
Detection Methods for CVE-2026-100593
Indicators of Compromise
- Unexpected /activation command invocations in group channel message logs originating from non-owner accounts
- Audit entries showing persistent activation policy changes without a corresponding owner action
- Observed shifts in agent response behavior, such as replies to messages that previously did not trigger activation
Detection Strategies
- Inventory deployed openclaw package versions across build manifests and package-lock.json files to identify instances below 2026.7.1
- Correlate /activation command events with the sender's channel role to flag non-owner invocations
- Alert on persistent activation policy transitions that occur outside documented change windows
Monitoring Recommendations
- Forward OpenClaw agent command logs to a centralized logging pipeline for retention and query
- Baseline the expected rate of activation policy changes per channel and alert on deviations
- Track owner-role assignments and compare them against the identity of users issuing configuration commands
How to Mitigate CVE-2026-100593
Immediate Actions Required
- Upgrade the openclaw npm package to version 2026.7.1 or later across all deployments
- Audit recent /activation command history in group channels for unauthorized changes and revert as needed
- Confirm the activation policy on each channel matches the owner's intended configuration after upgrade
Patch Information
The maintainers fixed the authorization gap in openclaw version 2026.7.1. The patch enforces the documented owner-only requirement for persistent /activation policy changes. Refer to the GitHub Security Advisory GHSA-q9j5-4xr6-xqqw for release details.
Workarounds
- Restrict channel send privileges to trusted members until the upgrade to 2026.7.1 is deployed
- Monitor and manually revert any unauthorized /activation changes while running an unpatched version
- Disable the OpenClaw agent in sensitive group channels where the activation policy cannot be reliably enforced
# Upgrade the vulnerable package to the fixed release
npm install openclaw@2026.7.1
npm ls openclaw
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.