{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@openclaw/matrix--2026.2.2--2026.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openclaw:matrix:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100541"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@openclaw/matrix (\u003e= 2026.2.2, \u003c 2026.8.1)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","access-control"],"_cs_type":"advisory","_cs_vendors":["OpenClaw"],"content_html":"\u003cp\u003eThe npm package @openclaw/matrix, used for integrating Matrix protocol communication with OpenClaw systems, contains an authorization vulnerability (CVE-2026-100541). The integration incorrectly applies lowercase normalization to Matrix user IDs during the process of deriving authorization identities. Crucially, this normalization process includes the server-name portion of the ID, which is case-sensitive by protocol definition.\u003c/p\u003e\n\u003cp\u003eThis logic flaw allows distinct, protocol-valid Matrix user accounts to map to the same internal authorization identity within OpenClaw. A malicious actor who can register or control a user ID that collides with an existing, privileged account via case or Unicode folding can effectively inherit the target's permissions. This grants the attacker unauthorized access to functions such as owner-level commands, plugin approvals, and execution privileges previously assigned to the legitimate user. The issue was addressed in version 2026.8.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privilege or external user to escalate their permissions to match those of an administrative account defined in the OpenClaw system. This can lead to unauthorized system command execution, unauthorized installation of malicious plugins, and full compromise of the OpenClaw environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for infrastructure and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @openclaw/matrix package to version 2026.8.1 or later immediately across all affected deployments.\u003c/li\u003e\n\u003cli\u003eReview OpenClaw authorization configurations to ensure that account allowlists and command-approval lists do not contain ambiguous or fold-colliding identifiers.\u003c/li\u003e\n\u003cli\u003eAudit existing logs for unauthorized command execution or plugin approval requests originating from Matrix identifiers that deviate in casing from the intended administrative accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T10:59:04Z","date_published":"2026-09-26T10:59:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-matrix-collision/","summary":"The @openclaw/matrix npm package (versions 2026.2.2 to 2026.8.0) fails to properly enforce case-sensitivity when deriving authorization identities from Matrix user IDs, potentially allowing unauthorized users to hijack administrative privileges.","title":"Authorization Bypass in @openclaw/matrix via Identifier Collision","url":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-matrix-collision/"}],"language":"en","title":"CraftedSignal Threat Feed - @Openclaw/Matrix (\u003e= 2026.2.2, \u003c 2026.8.1)","version":"https://jsonfeed.org/version/1.1"}