OpenClaw is an agent gateway distributed via npm. (CVE-2026-100592)
OpenClaw versions from 2026.4.10 up to but not including 2026.7.1 have a vulnerability where persistent memory dreaming commands can be issued by authorized users who are not owners, bypassing owner permission checks. This allows such users to enable or disable the Gateway's Memory Core dreaming behavior, potentially affecting the confidentiality, integrity, and availability of stored conversation data. The vulnerability is fixed in version 2026.7.1. Mitigation includes disabling dreaming commands in external channels or restricting command access to owners.
AI Analysis
Technical Summary
OpenClaw, an agent gateway distributed via npm, contains a vulnerability in versions >=2026.4.10 and <2026.7.1 where persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue persistent '/dreaming on' and '/dreaming off' commands to control the Gateway's Memory Core dreaming behavior, which disables or re-enables background memory processing contrary to owner expectations. Read-only and help commands remain properly controlled. The vulnerability is addressed in version 2026.7.1.
Potential Impact
An authorized user who is not the owner can manipulate the Gateway's memory dreaming state, potentially disrupting background memory processing or durable memory promotion. This can affect the confidentiality, integrity, and availability of stored conversation material depending on how memory is used subsequently. The impact is limited to authorized users with external-channel access but not ownership.
Mitigation Recommendations
The issue is fixed in OpenClaw version 2026.7.1. Until upgrading, it is recommended to disable dreaming commands in external channels or restrict command access to owners to prevent unauthorized memory dreaming state changes.
OpenClaw is an agent gateway distributed via npm. (CVE-2026-100592)
Description
OpenClaw versions from 2026.4.10 up to but not including 2026.7.1 have a vulnerability where persistent memory dreaming commands can be issued by authorized users who are not owners, bypassing owner permission checks. This allows such users to enable or disable the Gateway's Memory Core dreaming behavior, potentially affecting the confidentiality, integrity, and availability of stored conversation data. The vulnerability is fixed in version 2026.7.1. Mitigation includes disabling dreaming commands in external channels or restricting command access to owners.
CVSS v3.1
Score 6.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenClaw, an agent gateway distributed via npm, contains a vulnerability in versions >=2026.4.10 and <2026.7.1 where persistent memory dreaming mutations omit owner permission checks. An authorized but non-owner external-channel sender can issue persistent '/dreaming on' and '/dreaming off' commands to control the Gateway's Memory Core dreaming behavior, which disables or re-enables background memory processing contrary to owner expectations. Read-only and help commands remain properly controlled. The vulnerability is addressed in version 2026.7.1.
Potential Impact
An authorized user who is not the owner can manipulate the Gateway's memory dreaming state, potentially disrupting background memory processing or durable memory promotion. This can affect the confidentiality, integrity, and availability of stored conversation material depending on how memory is used subsequently. The impact is limited to authorized users with external-channel access but not ownership.
Mitigation Recommendations
The issue is fixed in OpenClaw version 2026.7.1. Until upgrading, it is recommended to disable dreaming commands in external channels or restrict command access to owners to prevent unauthorized memory dreaming state changes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-whch-3w2v-cfr2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100592"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab74f24f7a7c54106e12ebf
Added to database: 09/26/2026, 04:50:44 UTC
Last enriched: 09/26/2026, 04:52:15 UTC
Last updated: 09/26/2026, 05:47:48 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.