{"id":"CVE-2026-100575","published":"2026-09-26T03:17:05.030","lastModified":"2026-09-28T18:17:13.373","description":"OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-58qx-6m8p-wh2j","tags":[]},{"url":"https://www.vulncheck.com/advisories/openclaw-slack-before-2026.8.1-authentication-bypass-via-group-dm","tags":[]}],"exploitRefs":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-58qx-6m8p-wh2j","tags":[]}],"hasPoc":true,"ai":{"summary":"OpenClaw Slack versions before 2026.8.1 allow unauthorized participants to bypass sender policies and access tools and data intended for authorized agents, posing a significant security risk.","exploitability":"Exploitation is relatively straightforward as disallowed participants can trigger Slack agents, making it easy for attackers to gain unauthorized access.","blast_radius":"If exploited, this flaw could lead to unauthorized access to sensitive tools and data, potentially compromising the integrity and confidentiality of the Slack environment.","remediation":"Upgrade to OpenClaw Slack version 2026.8.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","data-access","slack"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:01:12.695Z"}}