๐Ÿ” CVE Alert

CVE-2026-26326

UNKNOWN 0.0

OpenClaw skills.status could leak secrets to operator.read clients

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only `{ path, satisfied }`) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to read-scoped clients.

CWE CWE-200
Vendor openclaw
Product openclaw
Published Feb 19, 2026
Last Updated Feb 20, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw

Be the first to know when new unknown vulnerabilities affecting openclaw openclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openclaw / openclaw
< 2026.2.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw/security/advisories/GHSA-8mh7-phf8-xgfm github.com: https://github.com/openclaw/openclaw/commit/d3428053d95eefbe10ecf04f92218ffcba55ae5a github.com: https://github.com/openclaw/openclaw/commit/ebc68861a61067fc37f9298bded3eec9de0ba783 github.com: https://github.com/openclaw/openclaw/releases/tag/v2026.2.14