PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100553 OpenClaw CVE debrief

CVE-2026-100553 is a vulnerability in OpenClaw versions >= 2026.6.9 and < 2026.8.1 that allows an admitted sender to remove a pin from another Feishu group, bypassing the intended cross-context message mutation policy when tools.message.crossContext.allowWithinProvider is disabled. The issue arises from OpenClaw's failure to declare the native chatId parameter as a delivery target in the Feishu unpin feature. This vulnerability has a medium severity and is fixed in OpenClaw version 2026.8.1.

Vendor
OpenClaw
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders responsible for OpenClaw deployments, particularly those using Feishu integration, should assess exposure and apply the patch to prevent unauthorized pin removal. This includes reviewing Feishu group authorization and membership, monitoring for unauthorized pin removal attempts, and verifying OpenClaw versions.

Why it matters

CVE-2026-100553 is a medium-severity vulnerability in OpenClaw that allows an admitted sender to bypass the intended cross-context message mutation policy, potentially leading to unauthorized pin removal from Feishu groups. Defenders should prioritize verifying OpenClaw versions and applying the patch to prevent this issue.

  • Potential unauthorized pin removal from Feishu groups
  • Bypassing of intended cross-context message mutation policy
  • Limited impact to message mutation (pin removal) only

Technical summary

OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, allowing an admitted sender to remove a pin from another Feishu group when tools.message.crossContext.allowWithinProvider is disabled. The vulnerability has a medium severity and is fixed in OpenClaw version 2026.8.1, with Feishu membership and group authorization still applying to limit the impact to message mutation (pin removal). Defenders should prioritize verifying OpenClaw versions and applying the patch.

Defensive priority

Defenders should prioritize verifying OpenClaw versions and applying the patch to prevent unauthorized pin removal.

Recommended defensive actions

  • Verify OpenClaw version and apply patch
  • Review Feishu group authorization and membership
  • Monitor for unauthorized pin removal attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The issue is fixed in OpenClaw version 2026.8.1. Feishu membership and group authorization still apply, and the demonstrated impact is limited to message mutation (pin removal). The vulnerability allows an admitted sender to bypass the intended cross-context message mutation policy when tools.message.crossContext.allowWithinProvider is disabled, potentially leading to unauthorized pin removal from Feishu groups.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100553 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100553

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100553 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100553

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.