PT-2026-99172 · Openclaw · Openclaw

CVE-2026-100535

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.5 through 2026.8.0
Description When session-derived text is persisted to session memory, the software may lose the restrictions and untrusted provenance of the originating requester. In deployments with session-memory capture and dreaming enabled, a restricted external sender can persist instructions that are subsequently processed by an unattended background (dreaming) agent. Because this agent may possess broader file and command capabilities, it can perform actions exceeding the original requester's authority, potentially affecting available files, commands, or services. Exploitation depends on the content being captured, selected for processing, and followed by the model.
Recommendations Update to version 2026.8.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100535
GHSA-62QM-6FJJ-6G23

Affected Products

Openclaw