Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100544— openclaw voice-call before 2026.8.1 Authorization Bypass

Quick assessment

Affected
openclaw voice-call
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 openclaw 的 包版本低于 2026.8.1 时,处理经典入站语音呼叫会启动配置的代理(agent),但未传播呼叫者的身份或非所有者状态。因此,仅允许所有者使用的工具过滤机制可能失效,导致远程呼叫者获得代理的常规工具权限。在启用了入站呼叫功能的部署中,如果呼叫者符合配置的入站呼叫策略(开放策略、配对策略或白名单策略),则该呼叫者可能操控原本仅供受信任的所有者使用的工具,根据代理的具体配置,这些工具可能具备读取数据、修改文件、执行命令或控制已连接服务等能力。该问题已在版本 2026.8.1 中修复。

CVSS 8.8 · High EPSS 0.25% · P14
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100544

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
openclaw voice-call before 2026.8.1 Authorization Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and expose the agent's normal tool authority to a remote caller. A caller who is admitted by the configured inbound-call policy (open, pairing, or allowlist) on a deployment with inbound calling enabled can therefore drive tools intended for the trusted owner, potentially reading data, modifying files, executing commands, or controlling connected services depending on the agent's configuration. The issue is fixed in 2026.8.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openclaw voice-call 0 ~ 2026.8.1 -

II. Public POCs for CVE-2026-100544

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100544

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100544 (1)

Other References for CVE-2026-100544 (1)

Same Patch Batch · openclaw · 2026-09-26 · 79 CVEs total

CVE-2026-100580 8.8 HIGH OpenClaw before 2026.7.1 Remote Code Execution via cron tool
CVE-2026-100575 8.8 HIGH OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM
CVE-2026-100596 8.8 HIGH OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
CVE-2026-100599 8.8 HIGH OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
CVE-2026-100587 8.8 HIGH OpenClaw before 2026.7.1 Authorization Bypass via Codex Install
CVE-2026-100586 8.8 HIGH OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind
CVE-2026-100552 8.8 HIGH OpenClaw before 2026.8.1 Policy Bypass via Native Tools
CVE-2026-100589 8.3 HIGH OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
CVE-2026-100588 8.3 HIGH OpenClaw before 2026.7.1 Authentication Bypass via node.invoke
CVE-2026-100568 8.3 HIGH OpenClaw before 2026.8.1 Unauthorized Command Job Access
CVE-2026-100551 8.3 HIGH OpenClaw iOS Control UI TLS Pin Enforcement Bypass
CVE-2026-100557 8.3 HIGH OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch
CVE-2026-100567 8.2 HIGH OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname
CVE-2026-100532 8.1 HIGH openclaw WhatsApp before 2026.8.1 Authentication Bypass
CVE-2026-100585 8.0 HIGH OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel
CVE-2026-100561 8.0 HIGH OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper
CVE-2026-100559 8.0 HIGH OpenClaw before 2026.8.1 Command Injection via Escaped Newlines
CVE-2026-100597 7.8 HIGH OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
CVE-2026-100570 7.8 HIGH OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS
CVE-2026-100578 7.6 HIGH OpenClaw before 2026.7.1 Authorization Bypass via chat.send

Showing top 20 of 79 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-100544

No comments yet


Leave a comment