OpenClaw is an npm-distributed agent gateway. (CVE-2026-100591)
OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable Active Memory for the Gateway, disabling memory recall for future sessions or re-enabling global recall where the owner expected it to remain disabled. The issue is limited to persistent global on/off mutations; session-level controls and read-only status remain governed by existing command policy. The issue is fixed in version 2026.7.1. (Suggested title: "OpenClaw before 2026.7.1 missing owner authorization check on Active Memory global toggles".)
AI Analysis
Technical Summary
OpenClaw, an npm-distributed agent gateway, contains an authorization bypass vulnerability in versions prior to 2026.7.1. Specifically, the global Active Memory toggle mutations do not properly verify owner authorization, allowing an authorized non-owner external-channel sender to persistently change the global Active Memory state. This can disable memory recall for future sessions or re-enable it when the owner expects it to remain disabled. The issue is limited to global on/off mutations; session-level controls and read-only status are unaffected. The vulnerability is addressed in version 2026.7.1.
Potential Impact
An authorized non-owner external-channel sender can persistently modify the global Active Memory state of the OpenClaw Gateway, potentially disrupting expected memory recall behavior across sessions. This could lead to unauthorized enabling or disabling of memory recall, impacting confidentiality, integrity, and availability of memory-related functions. However, session-level controls and read-only status remain protected by existing command policies.
Mitigation Recommendations
Upgrade OpenClaw to version 2026.7.1 or later, where the missing owner authorization check on global Active Memory toggles has been fixed. No additional mitigation is required as the issue is resolved in this official fix.
OpenClaw is an npm-distributed agent gateway. (CVE-2026-100591)
Description
OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender could therefore persistently enable or disable Active Memory for the Gateway, disabling memory recall for future sessions or re-enabling global recall where the owner expected it to remain disabled. The issue is limited to persistent global on/off mutations; session-level controls and read-only status remain governed by existing command policy. The issue is fixed in version 2026.7.1. (Suggested title: "OpenClaw before 2026.7.1 missing owner authorization check on Active Memory global toggles".)
CVSS v3.1
Score 6.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenClaw, an npm-distributed agent gateway, contains an authorization bypass vulnerability in versions prior to 2026.7.1. Specifically, the global Active Memory toggle mutations do not properly verify owner authorization, allowing an authorized non-owner external-channel sender to persistently change the global Active Memory state. This can disable memory recall for future sessions or re-enable it when the owner expects it to remain disabled. The issue is limited to global on/off mutations; session-level controls and read-only status are unaffected. The vulnerability is addressed in version 2026.7.1.
Potential Impact
An authorized non-owner external-channel sender can persistently modify the global Active Memory state of the OpenClaw Gateway, potentially disrupting expected memory recall behavior across sessions. This could lead to unauthorized enabling or disabling of memory recall, impacting confidentiality, integrity, and availability of memory-related functions. However, session-level controls and read-only status remain protected by existing command policies.
Mitigation Recommendations
Upgrade OpenClaw to version 2026.7.1 or later, where the missing owner authorization check on global Active Memory toggles has been fixed. No additional mitigation is required as the issue is resolved in this official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8rc9-6r79-j4mw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100591"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab74f26f7a7c54106e12eda
Added to database: 09/26/2026, 04:50:46 UTC
Last enriched: 09/26/2026, 04:53:28 UTC
Last updated: 09/27/2026, 04:31:11 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.