EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all intelligence correlata
Vulnerabilità

CVE-2026-100546

Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.

Condivisione
PUBLIC-OSINT
Confidenza
100
Fonte
The CVE Program
Aggiornata
26/09/2026 08:14

Descrizione

OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime voice transcript path. Concurrent control-classified voice transcripts could consume speaker context belonging to another participant after an asynchronous control check, causing a transcript to inherit another speaker's owner status. In Discord agent-proxy voice sessions using the affected realtime control path, an utterance from a non-owner participant could reach the downstream agent boundary marked as owner, so owner-sensitive behavior is applied to the wrong speaker. Exploitation depends on concurrent transcript timing and on the tools and commands available to the affected agent. The issue is fixed in 2026.9.2; as a workaround, disable Discord realtime voice for agents that distinguish owner and non-owner senders.

Identificativo STIXvulnerability--0b7866be-adde-5ec5-b104-00d82c0a6ed1
Prima osservazione-
Ultima osservazione-
Relazioni censite6

Alias e classificazioni

CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Dettagli tecnici minimizzati

Nessun dato grezzo
cisa kev
False
cvss score
6.4
cvss vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
cvss severity
MEDIUM
Correlazione EudorIA

Catalogo Intel

La vulnerabilit&agrave; &egrave; presente anche nel catalogo editoriale EudorIA.

Apri analisi EudorIA

La presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.