CVE-2026-100541: Improper Handling of Case Sensitivity in openclaw matrix
OpenClaw's Matrix integration (@openclaw/matrix) versions 2026.2.2 up to but not including 2026.8.1 improperly handle case sensitivity when deriving authorization identities by lowercasing complete Matrix user IDs, including case-sensitive server-name portions. This causes distinct authenticated Matrix accounts to normalize to the same authorization identity, allowing an attacker controlling a colliding account identifier to inherit elevated authorities such as allowlist, owner-command, exec-approval, or plugin-approval configured for another account. The issue is fixed in version 2026.8.1.
AI Analysis
Technical Summary
CVE-2026-100541 is a vulnerability in OpenClaw's Matrix integration npm package (@openclaw/matrix) where versions >=2026.2.2 and <2026.8.1 lowercase entire Matrix user IDs, including the case-sensitive server-name portion, when deriving authorization identities. This normalization causes distinct authenticated Matrix accounts that differ only by case or Unicode folding to be treated as the same authorization identity. Consequently, a Matrix participant controlling a colliding account identifier can inherit privileges assigned to another account, such as allowlist membership or command approvals. The vulnerability is resolved in version 2026.8.1.
Potential Impact
An attacker controlling a Matrix account whose identifier collides with another account's identifier after case normalization can gain unauthorized elevated privileges configured for the other account. This includes allowlist access, owner-command execution, exec-approval, or plugin-approval authority. This can lead to unauthorized actions within the OpenClaw Matrix environment. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade to OpenClaw Matrix integration version 2026.8.1 or later, where the issue is fixed. No other mitigation is required as the vulnerability is addressed by this official fix.
CVE-2026-100541: Improper Handling of Case Sensitivity in openclaw matrix
Description
OpenClaw's Matrix integration (@openclaw/matrix) versions 2026.2.2 up to but not including 2026.8.1 improperly handle case sensitivity when deriving authorization identities by lowercasing complete Matrix user IDs, including case-sensitive server-name portions. This causes distinct authenticated Matrix accounts to normalize to the same authorization identity, allowing an attacker controlling a colliding account identifier to inherit elevated authorities such as allowlist, owner-command, exec-approval, or plugin-approval configured for another account. The issue is fixed in version 2026.8.1.
CVSS v4.0
Score 7.7high
Affected software
openclaw
matrix
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100541 is a vulnerability in OpenClaw's Matrix integration npm package (@openclaw/matrix) where versions >=2026.2.2 and <2026.8.1 lowercase entire Matrix user IDs, including the case-sensitive server-name portion, when deriving authorization identities. This normalization causes distinct authenticated Matrix accounts that differ only by case or Unicode folding to be treated as the same authorization identity. Consequently, a Matrix participant controlling a colliding account identifier can inherit privileges assigned to another account, such as allowlist membership or command approvals. The vulnerability is resolved in version 2026.8.1.
Potential Impact
An attacker controlling a Matrix account whose identifier collides with another account's identifier after case normalization can gain unauthorized elevated privileges configured for the other account. This includes allowlist access, owner-command execution, exec-approval, or plugin-approval authority. This can lead to unauthorized actions within the OpenClaw Matrix environment. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade to OpenClaw Matrix integration version 2026.8.1 or later, where the issue is fixed. No other mitigation is required as the vulnerability is addressed by this official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T01:01:36.095Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab72eeef7a7c54106c273bf
Added to database: 09/26/2026, 02:33:18 UTC
Last enriched: 09/26/2026, 02:47:52 UTC
Last updated: 09/26/2026, 03:38:05 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.