OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to… (CVE-2026-100590)
OpenClaw versions prior to 2026.7.1 have an authorization bypass vulnerability in the /voice set command. This flaw allows non-owner external-channel senders with command access to persistently change the Gateway voice configuration used by Talk responses. The vulnerability affects configuration integrity but does not expose credentials or grant additional host capabilities.
AI Analysis
Technical Summary
CVE-2026-100590 describes an authorization bypass vulnerability in OpenClaw before version 2026.7.1. Specifically, the /voice set command can be exploited by non-owner external-channel senders who have command access to persist changes to the Gateway voice configuration. This allows attackers to alter the voice used by Talk responses for the configured provider, impacting the integrity of the configuration. The vulnerability does not disclose credentials or escalate privileges beyond configuration changes.
Potential Impact
The vulnerability allows attackers with command access but who are not owners to modify persistent voice configuration settings, potentially disrupting expected voice responses. There is no impact on confidentiality or availability, and no additional host capabilities are granted.
Mitigation Recommendations
A fix is available in OpenClaw version 2026.7.1. Users should upgrade to this version or later to remediate the authorization bypass vulnerability. No other mitigation steps are indicated.
OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to… (CVE-2026-100590)
Description
OpenClaw versions prior to 2026.7.1 have an authorization bypass vulnerability in the /voice set command. This flaw allows non-owner external-channel senders with command access to persistently change the Gateway voice configuration used by Talk responses. The vulnerability affects configuration integrity but does not expose credentials or grant additional host capabilities.
CVSS v3.1
Score 4.3medium
Affected software
pkg:github/openclaw/openclawRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100590 describes an authorization bypass vulnerability in OpenClaw before version 2026.7.1. Specifically, the /voice set command can be exploited by non-owner external-channel senders who have command access to persist changes to the Gateway voice configuration. This allows attackers to alter the voice used by Talk responses for the configured provider, impacting the integrity of the configuration. The vulnerability does not disclose credentials or escalate privileges beyond configuration changes.
Potential Impact
The vulnerability allows attackers with command access but who are not owners to modify persistent voice configuration settings, potentially disrupting expected voice responses. There is no impact on confidentiality or availability, and no additional host capabilities are granted.
Mitigation Recommendations
A fix is available in OpenClaw version 2026.7.1. Users should upgrade to this version or later to remediate the authorization bypass vulnerability. No other mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mh98-4wwc-cp33
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100590"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab74f26f7a7c54106e12ed8
Added to database: 09/26/2026, 04:50:46 UTC
Last enriched: 09/26/2026, 04:53:20 UTC
Last updated: 09/26/2026, 09:45:56 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.