High severity8.8NVD Advisory· Published Sep 26, 2026
CVE-2026-100575
CVE-2026-100575
Description
OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configured sender policies.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.