---
id: CVE-2026-100590
title: >-
  OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the
  /voice set command that allows non-owner external-channel senders to persist
  Gateway voice configuration
summary: >-
  OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the
  /voice set command that allows non-owner external-channel senders to persist
  Gateway voice configuration. Attackers with command access can change the
  voice u…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.7.1
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:17:07.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100590'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-5j27-v2pw-cj9m
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-authorization-bypass-via-voice-set
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.695Z'
---

## Overview

OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with command access can change the voice used by Talk responses for the configured provider, affecting configuration integrity without exposing credentials or granting additional host capabilities.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
