<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Slack (&lt; 2026.8.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/slack--2026.8.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 04:57:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/slack--2026.8.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in OpenClaw Slack</title><link>https://feed.craftedsignal.io/briefs/2026-09-openclaw-slack-auth-bypass/</link><pubDate>Sat, 26 Sep 2026 04:57:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openclaw-slack-auth-bypass/</guid><description>OpenClaw Slack versions prior to 2026.8.1 fail to enforce sender allowlists in multi-person direct messages, allowing unauthorized participants to interact with Slack agents and access restricted tools or data.</description><content:encoded><![CDATA[<p>OpenClaw Slack versions prior to 2026.8.1 contain an authentication bypass vulnerability, tracked as CVE-2026-100575, within the application's multi-person direct messaging component. The flaw stems from a failure to correctly validate sender allowlists when participants interact with automated agents configured within the chat environment. By bypassing these sender policies, an unauthorized or disallowed participant in a multi-person conversation can trigger agent execution, effectively masquerading as authorized users. This allows attackers to invoke tools and access sensitive data granted to the agent service accounts, potentially leading to unauthorized data exfiltration or manipulation of connected third-party services. Given the reliance on agent-based workflows, this vulnerability presents a significant risk to organizations using OpenClaw Slack for internal automation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized users within a multi-person chat thread to perform actions on behalf of Slack agents. This can result in unauthorized access to internal tools, data retrieval, and the potential execution of malicious commands or queries through agent-integrated systems. The scope of impact is limited to the permissions granted to the specific Slack agent compromised by the bypass.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade OpenClaw Slack installations to version 2026.8.1 or later immediately to resolve CVE-2026-100575.</li>
<li>Review and audit current Slack agent permissions to minimize the potential blast radius of unauthorized interactions.</li>
<li>Restrict sensitive agent integrations to dedicated channels where participant access can be strictly managed until the patch is deployed.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>authentication-bypass</category><category>cloud</category></item></channel></rss>