rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.7 · EPSS 0.00261

CVE-2026-100575

OpenClaw Slack versions prior to 2026.8.1 do not enforce sender allowlists in multi-person direct messages, allowing unauthorized participan

Overview

OpenClaw Slack versions prior to 2026.8.1 do not enforce sender allowlists in multi-person direct messages, allowing unauthorized participants to trigger Slack agents. This flaw lets attackers access tools and data that should be protected by configured policies. The vulnerability is critical and can lead to significant data exposure.

Description

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.

Impact

Confidentiality is compromised as disallowed users can access sensitive data and tools. Integrity is at risk because attackers can manipulate agent actions. Availability is indirectly affected if agents are misused to overload resources. Administrators and end‑users of OpenClaw Slack are directly impacted.

Remediation

Apply the 2026.8.1 patch or later immediately. Verify that sender allowlists are correctly configured for all multi‑person DMs. Disable or restrict multi‑person DMs for untrusted participants until the patch is applied. Monitor Slack agent activity for anomalous triggers and review policy enforcement logs.

Risk context

The CVSS v3 score of 8.8 and critical severity indicate a high risk, but the EPSS of 0.00261 suggests a low probability of exploitation in the near term. Nonetheless, defenders should treat this as a priority update.

Affected products

  • OpenClaw Slack

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
8.7
EPSS
0.00261

Slack allowlist direct-messages critical OpenClaw agent-bypass confidentiality

← All CVEs