Get real-time updates on Telegram
CVE-2026-100566: line 0 to before 2026.8.1
CVE-2026-100566. CVSS 3.1 base score 6.5 (MEDIUM, Vendor/CNA). EPSS 0.00201 (percentile 0.09138), scored 2026-10-06.
Affected technology
line · 0 to before 2026.8.1
openclaw
Description’s affected range: versions before 2026.8.1
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Attackers with group participation can trigger the agent despite configured group allowlist restrictions when DM access is broader than intended group access. Vendor/CNA’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-863
- CCR priority
- 26.1 /100 (P4)
- CVSS 3.1
- 6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N · Vendor/CNA
- EPSS
- 0.00201 · percentile 0.09182 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-100566.html