PT-2026-99162 · Npm · @Openclaw/Diagnostics-Prometheus
CVE-2026-100525
·
Published
2026-09-26
·
Updated
2026-09-26
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@openclaw/diagnostics-prometheus versions prior to 2026.9.3
Description
The authenticated metrics endpoint fails to enforce the
operator.read scope. In deployments utilizing identity-bearing Gateway authentication modes, such as trusted-proxy, an authenticated caller without the required read scope can retrieve the diagnostics document. This occurs even when standard read methods correctly reject the identity, leading to the disclosure of operational metrics to profiles with restricted access.Recommendations
Update to version 2026.9.3.
Disable the Prometheus endpoint as a temporary workaround.
Ensure every identity capable of reaching the endpoint is intended to hold the
operator.read scope.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Openclaw/Diagnostics-Prometheus