PatchSiren cyber security CVE debrief
CVE-2026-100556 OpenClaw CVE debrief
CVE-2026-100556 is a vulnerability in the OpenClaw npm package that allows a group sender to reset the shared group session and persist a provider and model override, potentially changing provider routing, cost, data flow, or availability. This issue affects WhatsApp group handling configurations and OpenClaw npm package deployments. Defenders should assess exposure and prioritize verification and remediation. The vulnerability is fixed in version 2026.8.1 and affects versions >= 2026.5.2 and < 2026.8.1.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for WhatsApp group handling configurations and OpenClaw npm package deployments should assess exposure and prioritize verification and remediation. This includes reviewing configurations, verifying affected scope, and planning vendor-supported updates or mitigations.
Why it matters
Defenders should care about CVE-2026-100556 because it allows a group sender to reset the shared group session and persist a provider and model override, potentially changing provider routing, cost, data flow, or availability. This requires verification and remediation priority for WhatsApp group handling configurations and OpenClaw npm package deployments.
- Potential changes in provider routing
- Potential changes in cost and data flow
- Potential changes in availability
Technical summary
The OpenClaw npm package versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in WhatsApp group handling. A group sender who is admitted for ordinary messages but denied by commands.allowFrom or owner command authorization can issue the /new <model> command to reset the shared group session and persist a provider and model override. This allows a command-denied group member to select a provider and model already permitted by the operator for subsequent turns in the shared group session, potentially changing provider routing, cost, data flow, or availability.
Defensive priority
Defenders should prioritize verifying and upgrading to version 2026.8.1 or later, and review WhatsApp group handling configurations.
Recommended defensive actions
- Verify and upgrade to version 2026.8.1 or later
- Review WhatsApp group handling configurations
- Monitor for potential changes in provider routing, cost, data flow, or availability
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is described in the CVE record and NVD vulnerability detail page. The issue is fixed in version 2026.8.1. There are no additional details on the number of affected deployments or specific changes in provider routing, cost, data flow, or availability. However, defenders should verify WhatsApp group handling configurations and OpenClaw npm package deployments for potential exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100556 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100556
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100556 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100556
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-mm7m-wcgh-8mfq
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-authentication-bypass-via-session-reset
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.