Authentication Bypass in OpenClaw Node Package by OpenClaw
CVE-2026-100588
8.7HIGH
What is CVE-2026-100588?
The OpenClaw npm package before version 2026.7.1 contains an authentication bypass vulnerability which allows a write-scoped caller with access to a browser-capable node to interact with browser-visible applications without proper administrative authority. This is particularly concerning in Gateway deployments that respect caller identity and narrower operator scopes. Attackers could potentially inspect pages or navigate tabs while remaining unchecked under the current security model. It is important to note that shared-secret token and password callers are not affected by this issue, but the lack of scope enforcement could lead to significant security risks for other users.
Affected Version(s)
OpenClaw 0 < 2026.7.1
OpenClaw 2026.7.1
