PT-2026-97056 · Openclaw · Openclaw
CVSS v4.0
7.2
High
| Vector | AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw iOS versions prior to 2026.8.11
Description
The application logs complete agent deep-link URLs, which include persistent bearer keys, to unified logs as public diagnostic data. Bearer keys are security tokens that grant access to a resource without requiring further authentication. An attacker who obtains diagnostic archives can recover these unrotated keys and use them in forged deep links to submit agent requests without triggering local confirmation prompts.
Recommendations
Update to version 2026.8.11 or later.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw