CVE-2026-100544: Missing Authorization in openclaw voice-call
CVE-2026-100544 is a high-severity vulnerability in the openclaw voice-call package before version 2026.8.1. The flaw allows inbound callers admitted by the deployment's inbound-call policy to access owner-only tools without proper authorization. This occurs because the caller's identity and non-owner status are not propagated when launching the configured agent for classic inbound voice calls. Exploitation can lead to unauthorized reading, modification, execution, or control of services depending on the agent's configuration. The issue is fixed in version 2026.8.1.
AI Analysis
Technical Summary
The openclaw voice-call package prior to 2026.8.1 has a missing authorization check when launching the configured agent for classic inbound voice calls. Specifically, the caller's identity and non-owner status are not propagated, causing owner-only tool filtering to fail open. Consequently, a remote caller admitted by the inbound-call policy can use tools intended for the trusted owner, potentially leading to unauthorized data access, file modification, command execution, or control over connected services. The vulnerability is resolved in version 2026.8.1.
Potential Impact
An attacker who is allowed by the inbound-call policy to place a call can gain unauthorized access to owner-only tools on the agent. This can result in reading sensitive data, modifying files, executing arbitrary commands, or controlling connected services, depending on the agent's configuration. The vulnerability compromises the intended access controls and can lead to significant unauthorized actions.
Mitigation Recommendations
Upgrade the openclaw voice-call package to version 2026.8.1 or later, where this authorization issue is fixed. No other mitigations are specified. Patch status is confirmed by the vendor advisory stating the fix is in 2026.8.1.
CVE-2026-100544: Missing Authorization in openclaw voice-call
Description
CVE-2026-100544 is a high-severity vulnerability in the openclaw voice-call package before version 2026.8.1. The flaw allows inbound callers admitted by the deployment's inbound-call policy to access owner-only tools without proper authorization. This occurs because the caller's identity and non-owner status are not propagated when launching the configured agent for classic inbound voice calls. Exploitation can lead to unauthorized reading, modification, execution, or control of services depending on the agent's configuration. The issue is fixed in version 2026.8.1.
CVSS v4.0
Score 8.7high
Affected software
openclaw
voice-call
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The openclaw voice-call package prior to 2026.8.1 has a missing authorization check when launching the configured agent for classic inbound voice calls. Specifically, the caller's identity and non-owner status are not propagated, causing owner-only tool filtering to fail open. Consequently, a remote caller admitted by the inbound-call policy can use tools intended for the trusted owner, potentially leading to unauthorized data access, file modification, command execution, or control over connected services. The vulnerability is resolved in version 2026.8.1.
Potential Impact
An attacker who is allowed by the inbound-call policy to place a call can gain unauthorized access to owner-only tools on the agent. This can result in reading sensitive data, modifying files, executing arbitrary commands, or controlling connected services, depending on the agent's configuration. The vulnerability compromises the intended access controls and can lead to significant unauthorized actions.
Mitigation Recommendations
Upgrade the openclaw voice-call package to version 2026.8.1 or later, where this authorization issue is fixed. No other mitigations are specified. Patch status is confirmed by the vendor advisory stating the fix is in 2026.8.1.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T01:01:36.095Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab72eeef7a7c54106c273c0
Added to database: 09/26/2026, 02:33:18 UTC
Last enriched: 09/26/2026, 02:47:49 UTC
Last updated: 09/26/2026, 03:19:04 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.