Credential Exposure in OpenClaw iOS by OpenClaw
CVE-2026-95815
7.2HIGH
What is CVE-2026-95815?
The OpenClaw iOS application prior to version 2026.8.11 exposes sensitive data by logging complete agent deep-link URLs, which include persistent bearer keys. These logs are saved as public diagnostic data. If an attacker gains access to these diagnostic archives, they can retrieve the unrotated keys and use them to forge deep links. This enables unauthorized agent requests without local confirmations, posing a significant security risk.
Affected Version(s)
OpenClaw iOS 0 < 2026.8.11
OpenClaw iOS 2026.8.11
