PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100532 openclaw CVE debrief

CVE-2026-100532 debrief based on the supplied source corpus. The @openclaw/whatsapp (npm) package before version 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the owner's status. This allows an admitted non-owner sender to request a forced login and receive a new QR code for a configured account, potentially disconnecting the Gateway's WhatsApp account and causing loss of availability. Defenders should assess their exposure and take necessary actions to mitigate the vulnerability.

Vendor
openclaw
Product
whatsapp
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders responsible for maintaining and securing systems that use the @openclaw/whatsapp (npm) package should assess their exposure and take necessary actions to mitigate the vulnerability.

Why it matters

Defenders should care about CVE-2026-100532 because it affects the @openclaw/whatsapp (npm) package and can lead to potential loss of availability and unauthorized access. Relevant roles include system administrators and security teams responsible for maintaining and securing systems that use this package. The vulnerability requires verification of the package version and upgrading to 2026.8.1 or later. Evidence is limited to the CVE record and NVD entry.

  • Potential loss of availability of the WhatsApp account due to forced login and QR code generation.
  • Possible unauthorized access to the WhatsApp account if the attacker scans the returned QR code with another phone.

Technical summary

The @openclaw/whatsapp (npm) package before version 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the owner's status. This allows an admitted non-owner sender to request a forced login and receive a new QR code for a configured account, potentially disconnecting the Gateway's WhatsApp account and causing loss of availability. The issue affects the owner-only tool boundary rather than WhatsApp transport authentication. Fixed in 2026.8.1. Defenders should prioritize verifying and upgrading to version 2026.8.1 or later.

Defensive priority

Defenders should prioritize verifying and upgrading to version 2026.8.1 or later.

Recommended defensive actions

  • Verify the @openclaw/whatsapp package version and upgrade to 2026.8.1 or later if necessary.
  • Review and restrict access to the WhatsApp login tool to ensure only authorized users can access it.
  • Monitor for any suspicious activity related to the WhatsApp login tool.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in @openclaw/whatsapp (npm) before version 2026.8.1. Evidence is limited to the CVE record, NVD entry, and source references. Defenders should verify the package version and review the WhatsApp login tool access. The vulnerability affects the owner-only tool boundary rather than WhatsApp transport authentication.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100532 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100532

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100532 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100532

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.