Credential Exposure in OpenClaw iOS by OpenClaw
CVE-2026-95815

7.2HIGH

Key Information:

Vendor

Openclaw

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95815?

The OpenClaw iOS application prior to version 2026.8.11 exposes sensitive data by logging complete agent deep-link URLs, which include persistent bearer keys. These logs are saved as public diagnostic data. If an attacker gains access to these diagnostic archives, they can retrieve the unrotated keys and use them to forge deep links. This enables unauthorized agent requests without local confirmations, posing a significant security risk.

Affected Version(s)

OpenClaw iOS 0 < 2026.8.11

OpenClaw iOS 2026.8.11

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jason O'Neal (jason-allen-oneal)
.