Control UI TLS Pin Enforcement Bypass in OpenClaw for iOS by OpenClaw
CVE-2026-100551

9CRITICAL

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100551?

The OpenClaw for iOS application versions between 2026.7.1 and 2026.8.11 have a vulnerability that allows attackers to bypass TLS pin enforcement in the Control UI. This issue arises because while native connections properly enforce the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews do not. An attacker able to redirect to the same host and port can present a different certificate accepted by the iOS system trust, thus serving a malicious Control UI page. This could lead to the unauthorized extraction of sensitive user credentials, including tokens or passwords, potentially granting the attacker unauthorized operator access to critical Gateway state data.

Affected Version(s)

OpenClaw 2026.7.1 < 2026.8.11

OpenClaw 2026.8.11

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xca1x
migraine-sudo
.