Authentication Bypass in OpenClaw Node Package by OpenClaw
CVE-2026-100588

8.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100588?

The OpenClaw npm package before version 2026.7.1 contains an authentication bypass vulnerability which allows a write-scoped caller with access to a browser-capable node to interact with browser-visible applications without proper administrative authority. This is particularly concerning in Gateway deployments that respect caller identity and narrower operator scopes. Attackers could potentially inspect pages or navigate tabs while remaining unchecked under the current security model. It is important to note that shared-secret token and password callers are not affected by this issue, but the lack of scope enforcement could lead to significant security risks for other users.

Affected Version(s)

OpenClaw 0 < 2026.7.1

OpenClaw 2026.7.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wwwvwwvwwwwwvwwvw
.