{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenclawopenclaw_whatsapp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openclaw:openclaw_whatsapp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-100532"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@openclaw/whatsapp (\u003c 2026.8.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","npm","supply-chain"],"_cs_type":"advisory","_cs_vendors":["openclaw"],"content_html":"\u003cp\u003eThe @openclaw/whatsapp npm package, used for integrating WhatsApp functionality, contains a critical authorization flaw (CVE-2026-100532) in versions prior to 2026.8.1. The vulnerability stems from a failure to enforce the 'owner-only' security boundary on the generic channel-tool path used for the WhatsApp login process.\u003c/p\u003e\n\u003cp\u003eBy design, the login tool should only be accessible to the configured owner of the service. However, because the tool fails to preserve or validate the sender's owner status during the interaction, any non-owner user capable of steering the tool can invoke the login functionality. This action forces the service to generate a new QR code for a configured account. This process effectively disconnects the currently active WhatsApp account from the Gateway, leading to a denial-of-service condition. While the primary impact is service disruption, an attacker with physical access to the device can perform a subsequent QR code scan to relink the gateway to an account of their choosing, leading to unauthorized account control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to immediate denial-of-service as the active WhatsApp account is disconnected from the Gateway. In scenarios where an attacker can scan the newly generated QR code, they can hijack the gateway's WhatsApp integration. This vulnerability affects all environments deploying @openclaw/whatsapp versions earlier than 2026.8.1.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the @openclaw/whatsapp dependency to version 2026.8.1 or later.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized access attempts to the login tool path or unexpected QR code generation events triggered by non-administrative service accounts.\u003c/li\u003e\n\u003cli\u003eImplement stricter access control logic at the application layer if upgrading is delayed, ensuring only authorized user IDs are permitted to interact with the channel-tool path.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T06:57:05Z","date_published":"2026-09-26T06:57:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-whatsapp-auth-bypass/","summary":"The @openclaw/whatsapp npm package prior to version 2026.8.1 contains an authorization bypass vulnerability (CVE-2026-100532) allowing non-owner users to trigger the WhatsApp login tool, resulting in service disruption via account disconnection.","title":"Authorization Bypass in @openclaw/whatsapp npm package","url":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-whatsapp-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openclaw:openclaw_whatsapp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}