Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity. | |
| Title | OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account | |
| First Time appeared |
Openclaw
Openclaw openclaw\/feishu |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openclaw:openclaw\/feishu:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw\/feishu |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T02:18:38.549Z
Reserved: 2026-09-26T01:01:36.095Z
Link: CVE-2026-100540
No data.
Status : Received
Published: 2026-09-26T03:16:59.833
Modified: 2026-09-26T03:16:59.833
Link: CVE-2026-100540
No data.
OpenCVE Enrichment
Updated: 2026-09-26T07:45:06Z
-
CWE-863
Incorrect Authorization