Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-26

HighVendor post

OpenClaw Channel Tools Could Read Rooms Excluded by Operator Policy

Analysis of CVE-2026-100582, where explicit channel targets could bypass OpenClaw read allowlists for Teams, Feishu, Matrix, and Google Chat.

OpenClaw channel pluginsCredential exposureMissing resource-scope authorization in agent-accessible channel read actionsOpenClaw Microsoft Teams, Feishu, Matrix, and Google Chat plugins before version 2026.8.1

What happened

In the disclosed scenario, a lower-trust sender or steered agent supplies an explicit room target to a channel read action and retrieves content or metadata from a room excluded by the operator's configured read policy.

Why it matters

Potential disclosure of messages, reactions, pins, membership information, and related metadata from Teams, Feishu, Matrix, or Google Chat rooms accessible to the bot but excluded from the agent's allowlist.

Missing authorization check

A use-time decision binding the authenticated caller, agent, provider account, exact room or channel, operation, and current read policy before the plugin contacts the provider.

Would PP block it?

The gate would compare the caller, agent, provider, room identifier, operation, and current policy before issuing the provider request. An explicit target outside the approved resource set would lack a matching receipt and fail closed.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-09-26

    CVE-2026-100582 and GHSA-g7fw-3gjp-g5hf are published for the OpenClaw channel read allowlist bypass.

  2. 2026-09-26

    OpenClaw 2026.8.1 is identified as the fixed release.

Technical breakdown

  • Operators configured read allowlists intended to limit which rooms the connected agent could inspect.
  • Message, reaction, pin, member, and related metadata actions accepted caller-supplied explicit targets.
  • The affected plugins did not apply the configured read allowlist to those explicit targets.
  • The provider returned data whenever the connected bot account itself had permission, even if operator policy excluded that room.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Channel plugin boundary immediately before each provider API read
Still needs
Permission Protocol does not patch OpenClaw, revoke the bot account's provider permissions, or prevent disclosure through ungated provider clients.
Receipt required for
Reading the specified message, reaction, pin, member list, or metadata from a named Teams, Feishu, Matrix, or Google Chat room

A Tool-Call Gate can require authority for the exact channel target and read operation instead of inheriting blanket access from the connected bot account.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop