Authorization Bypass in OpenClaw by OpenClaw
CVE-2026-100557

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100557?

OpenClaw has a vulnerability that allows non-owner senders to execute skill commands and access tools meant for owner use. This flaw arises from an authorization bypass in the skill tool dispatch mechanism, which neglects to verify the owner status of the sender. As a result, unauthorized users can gain access to privileged tools and sensitive server credentials intended solely for owners, leading to potential security risks.

Affected Version(s)

OpenClaw 0 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SEORY0
.