Skip to main content
Vulnerability Database/CVE-2026-100593

CVE-2026-100593: OpenClaw npm Package Auth Bypass Flaw

CVE-2026-100593 is an authorization bypass vulnerability in the OpenClaw npm package allowing non-owner users to modify activation policies in group channels. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100593 Overview

CVE-2026-100593 affects the openclaw npm package in versions prior to 2026.7.1. The package fails to enforce its documented owner-only requirement for persistent /activation policy changes inside group channels. An authorized non-owner sender can modify whether the agent requires mention-based activation. This causes the agent to respond more broadly to group traffic or to suppress expected activation behavior until an owner restores the configured setting. The flaw is classified under CWE-862: Missing Authorization and is fixed in 2026.7.1.

Critical Impact

Any authorized channel sender can toggle the agent's activation policy, altering response scope across the group without owner consent.

Affected Products

  • openclaw npm package versions prior to 2026.7.1
  • OpenClaw agent deployments integrated into group channel environments
  • Downstream applications bundling vulnerable openclaw releases

Discovery Timeline

  • 2026-09-26 - CVE-2026-100593 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100593

Vulnerability Analysis

The vulnerability is a missing authorization check on the /activation command handler in group channels. OpenClaw documents the /activation policy as owner-only. The implementation does not validate the sender's role before persisting the change. Any user already authorized to send messages in the channel can issue the command. The change persists until an owner reverts it.

The practical result is a configuration drift primitive. By disabling mention-based activation, an attacker widens the agent's response surface so it reacts to additional group traffic. By enabling it unexpectedly, an attacker silences the agent until the owner notices. Both outcomes affect integrity and confidentiality of the agent's interaction model within the channel.

Root Cause

The root cause is an authorization gap in the /activation command path. The handler trusts the sender's existing channel-send permission as sufficient. It does not verify that the sender holds the owner role before applying a persistent configuration change. This matches the CWE-862 pattern of missing authorization on a state-changing operation.

Attack Vector

Exploitation requires network access to the group channel and a valid non-owner account with send privileges. No user interaction from the owner is required. The attacker submits the /activation command with the target policy value. The agent persists the setting and begins operating under the attacker-chosen activation mode. See the GitHub Security Advisory GHSA-q9j5-4xr6-xqqw and the VulnCheck advisory for additional context.

Detection Methods for CVE-2026-100593

Indicators of Compromise

  • Unexpected /activation command invocations in group channel message logs originating from non-owner accounts
  • Audit entries showing persistent activation policy changes without a corresponding owner action
  • Observed shifts in agent response behavior, such as replies to messages that previously did not trigger activation

Detection Strategies

  • Inventory deployed openclaw package versions across build manifests and package-lock.json files to identify instances below 2026.7.1
  • Correlate /activation command events with the sender's channel role to flag non-owner invocations
  • Alert on persistent activation policy transitions that occur outside documented change windows

Monitoring Recommendations

  • Forward OpenClaw agent command logs to a centralized logging pipeline for retention and query
  • Baseline the expected rate of activation policy changes per channel and alert on deviations
  • Track owner-role assignments and compare them against the identity of users issuing configuration commands

How to Mitigate CVE-2026-100593

Immediate Actions Required

  • Upgrade the openclaw npm package to version 2026.7.1 or later across all deployments
  • Audit recent /activation command history in group channels for unauthorized changes and revert as needed
  • Confirm the activation policy on each channel matches the owner's intended configuration after upgrade

Patch Information

The maintainers fixed the authorization gap in openclaw version 2026.7.1. The patch enforces the documented owner-only requirement for persistent /activation policy changes. Refer to the GitHub Security Advisory GHSA-q9j5-4xr6-xqqw for release details.

Workarounds

  • Restrict channel send privileges to trusted members until the upgrade to 2026.7.1 is deployed
  • Monitor and manually revert any unauthorized /activation changes while running an unpatched version
  • Disable the OpenClaw agent in sensitive group channels where the activation policy cannot be reliably enforced
bash
# Upgrade the vulnerable package to the fixed release
npm install openclaw@2026.7.1
npm ls openclaw

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.