What happened
In the disclosed scenario, a lower-trust sender or steered agent supplies an explicit room target to a channel read action and retrieves content or metadata from a room excluded by the operator's configured read policy.
2026-09-26
HighVendor postAnalysis of CVE-2026-100582, where explicit channel targets could bypass OpenClaw read allowlists for Teams, Feishu, Matrix, and Google Chat.
What happened
In the disclosed scenario, a lower-trust sender or steered agent supplies an explicit room target to a channel read action and retrieves content or metadata from a room excluded by the operator's configured read policy.
Why it matters
Potential disclosure of messages, reactions, pins, membership information, and related metadata from Teams, Feishu, Matrix, or Google Chat rooms accessible to the bot but excluded from the agent's allowlist.
Missing authorization check
A use-time decision binding the authenticated caller, agent, provider account, exact room or channel, operation, and current read policy before the plugin contacts the provider.
Would PP block it?
The gate would compare the caller, agent, provider, room identifier, operation, and current policy before issuing the provider request. An explicit target outside the approved resource set would lack a matching receipt and fail closed.
Incident analysis
2026-09-26
CVE-2026-100582 and GHSA-g7fw-3gjp-g5hf are published for the OpenClaw channel read allowlist bypass.
2026-09-26
OpenClaw 2026.8.1 is identified as the fixed release.
Authorization boundary
This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Tool-Call Gate can require authority for the exact channel target and read operation instead of inheriting blanket access from the connected bot account.
Related incidents and controls
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.