Impact
A lower‑trust caller or a specially configured input path in OpenClaw Feishu tools (npm package @openclaw/feishu) can bypass per‑account disablement checks, allowing an attacker to perform privileged actions that should have required stronger authorization. The flaw enables unauthorized operations and therefore poses a risk of data exposure or manipulation. This vulnerability is characterized as a CWE‑863 fault, reflecting a failure to verify access rights before executing configuration changes or resource operations.
Affected Systems
The affected component is the OpenClaw Feishu tools package for Feishu. Versions up to and including 2026.6.6 are vulnerable. The issue was fixed in version 2026.6.9; any deployment using that or newer releases is considered safe. Systems that rely on @openclaw/feishu and have not upgraded past 2026.6.6 are at risk.
Risk and Exploitability
The CVSS score of 8.6 places this flaw in the high‑severity range, indicating that an adversary could achieve significant impact if exploited. The EPSS score is less than 1 %, which suggests that the likelihood of exploitation is low, though not zero. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely to be remote or local depending on how the Feishu tool is exposed; a lower‑trust caller or malicious input path that the tool accepts can trigger the bypass.
OpenCVE Enrichment