---
id: CVE-2026-100566
title: >-
  OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability
  where group allowlist mode silently inherits DM allowFrom values when
  groupAllowFrom is not explicitly configured
summary: >-
  OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability
  where group allowlist mode silently inherits DM allowFrom values when
  groupAllowFrom is not explicitly configured. Attackers with group
  participation can trig…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: openclaw
product: line
affected:
  - line < 2026.8.1
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:17:03.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100566'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-fgwg-c3wv-8f45
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-line-before-2026.8.1-access-control-inheritance
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.687Z'
epss: 0.00201
epssPercentile: 0.09008
---

## Overview

OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. Attackers with group participation can trigger the agent despite configured group allowlist restrictions when DM access is broader than intended group access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
