Canvas Capability Revocation Bypass in OpenClaw by OpenClaw
CVE-2026-100554

2.3LOW

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100554?

The OpenClaw npm package experiences a vulnerability that fails to immediately invalidate Canvas HTTP authorization upon node revocation. While a revoked node will lose its WebSocket client capabilities, it retains Canvas HTTP authorization until a cleanup process occurs, allowing it to exploit its capabilities on designated routes momentarily. This issue affects versions from 2026.5.12 to under 2026.8.1 and has been addressed in version 2026.8.1. To mitigate the risk during the cleanup, a workaround involves restarting the Gateway after revoking a node with Canvas access.

Affected Version(s)

OpenClaw 2026.5.12 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andrewCantina
.