๐Ÿ” CVE Alert

CVE-2026-100588

HIGH 8.3

OpenClaw before 2026.7.1 Authentication Bypass via node.invoke

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without the configured admin requirement; practical impact depends on the browser profile and signed-in state. Shared-secret token and password callers are considered fully trusted operators under OpenClaw's security model and are not affected. The issue is fixed in 2026.7.1.

CWE CWE-863
Vendor openclaw
Product openclaw
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw

Be the first to know when new high vulnerabilities affecting openclaw openclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

OpenClaw / OpenClaw
0 < 2026.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-jghr-xp78-995p vulncheck.com: https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-authentication-bypass-via-node-invoke

Credits

๐Ÿ” wwwvwwvwwwwwvwwvw