Impact
OpenClaw Feishu versions before 2026.6.9 contain an incorrect authorization flaw that allows a lower‑trust caller or crafted input to perform actions that normally require stronger policy checks. This privilege escalation, classified as CWE‑863, can lead to unauthorized modification or exposure of Feishu data. The vulnerability arises from the Feishu permission tools ignoring per‑account disablement settings when the feature is enabled and reachable.
Affected Systems
The affected product is OpenClaw Feishu (vendor openclaw:feishu). Deployments running version 2026.6.6 or earlier are vulnerable. The issue was fixed in 2026.6.9; any older deployments should be updated.
Risk and Exploitability
The CVSS score of 8.6 indicates a high‑severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. Based on the description, the likely attack vector is an external caller that leverages the enabled Feishu permission tools feature to send crafted inputs or manipulate input paths, bypassing the required policy checks. This flaw is not listed in the CISA KEV catalog, but its high severity and potential for privilege escalation warrant near‑term action.
OpenCVE Enrichment