Authorization Bypass in OpenClaw by OpenClaw
CVE-2026-100557
8.7HIGH
What is CVE-2026-100557?
OpenClaw has a vulnerability that allows non-owner senders to execute skill commands and access tools meant for owner use. This flaw arises from an authorization bypass in the skill tool dispatch mechanism, which neglects to verify the owner status of the sender. As a result, unauthorized users can gain access to privileged tools and sensitive server credentials intended solely for owners, leading to potential security risks.
Affected Version(s)
OpenClaw 0 < 2026.8.1
OpenClaw 2026.8.1
