PT-2026-99162 · Npm · @Openclaw/Diagnostics-Prometheus

CVE-2026-100525

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @openclaw/diagnostics-prometheus versions prior to 2026.9.3
Description The authenticated metrics endpoint fails to enforce the operator.read scope. In deployments utilizing identity-bearing Gateway authentication modes, such as trusted-proxy, an authenticated caller without the required read scope can retrieve the diagnostics document. This occurs even when standard read methods correctly reject the identity, leading to the disclosure of operational metrics to profiles with restricted access.
Recommendations Update to version 2026.9.3. Disable the Prometheus endpoint as a temporary workaround. Ensure every identity capable of reaching the endpoint is intended to hold the operator.read scope.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100525
GHSA-RX8P-QCPV-C7VR

Affected Products

@Openclaw/Diagnostics-Prometheus