Credential Storage Vulnerability in OpenClaw for iOS
CVE-2026-100581

6.8MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100581?

OpenClaw for iOS versions prior to 2026.8.11 have a significant security issue where sensitive Gateway credentials are stored in plain text within the App Group UserDefaults instead of the secure device Keychain. This design flaw allows attackers who gain access to unencrypted device backups or the App Group container to easily retrieve valid Gateway tokens and passwords, potentially enabling them to authenticate as legitimate operators and gain unauthorized access.

Affected Version(s)

OpenClaw 0 < 2026.8.11

OpenClaw 2026.8.11

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yetval
.