Impact
The vulnerability is a race condition in OpenClaw’s Discord realtime voice transcript path, where concurrent control-classified voice transcripts can consume speaker context belonging to another participant after an asynchronous control check. This race condition allows an utterance from a non-owner participant to be marked as owned, causing owner-sensitive behavior to be applied to the wrong speaker. The flaw represents an authentication bypass that can lead to unintended privileged actions within the agent’s environment.
Affected Systems
Affected products are the OpenClaw npm package with versions starting at 2026.7.2 and ending before 2026.9.2. Any deployment that includes the affected realtime control path on Discord agent-proxy voice sessions is vulnerable, regardless of the host operating system or other language runtimes.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and EPSS is not available, suggesting no publicly known exploit yet. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires precisely timed concurrent transcripts and the presence of the agent’s command set, which limits the attack surface. Still, the attack vector is inferred to be via the normal operation of Discord voice sessions, so users with direct control over those sessions can trigger the behavior. The fix is available in version 2026.9.2, and a temporary workaround is to disable Discord realtime voice for affected agents.
OpenCVE Enrichment