๐Ÿ” CVE Alert

CVE-2026-100525

MEDIUM 4.3

OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read scope can retrieve the diagnostics document even though ordinary read methods reject the same identity, disclosing operational metrics to an authenticated profile intentionally limited below read access. Shared-secret Gateway callers already hold the documented full operator scope and are not affected. The issue is fixed in 2026.9.3; as a workaround, disable the Prometheus endpoint or ensure every identity that can reach it is intended to hold operator.read.

CWE CWE-862
Vendor openclaw
Product diagnostics-prometheus
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw diagnostics-prometheus

Be the first to know when new medium vulnerabilities affecting openclaw diagnostics-prometheus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

openclaw / diagnostics-prometheus
0 < 2026.9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-rx8p-qcpv-c7vr vulncheck.com: https://www.vulncheck.com/advisories/openclaw-diagnostics-prometheus-before-2026.9.3-authentication-bypass