๐Ÿ” CVE Alert

CVE-2026-100540

MEDIUM 6.8

OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity.

CWE CWE-863
Vendor openclaw
Product feishu
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw feishu

Be the first to know when new medium vulnerabilities affecting openclaw feishu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

openclaw / feishu
0 < 2026.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-h2qg-fxpv-82v6 vulncheck.com: https://www.vulncheck.com/advisories/openclaw-feishu-before-2026.8.1-authentication-bypass-via-disabled-account