PT-2026-99172 · Openclaw · Openclaw
CVE-2026-100535
·
Published
2026-09-26
·
Updated
2026-09-26
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.5 through 2026.8.0
Description
When session-derived text is persisted to session memory, the software may lose the restrictions and untrusted provenance of the originating requester. In deployments with session-memory capture and dreaming enabled, a restricted external sender can persist instructions that are subsequently processed by an unattended background (dreaming) agent. Because this agent may possess broader file and command capabilities, it can perform actions exceeding the original requester's authority, potentially affecting available files, commands, or services. Exploitation depends on the content being captured, selected for processing, and followed by the model.
Recommendations
Update to version 2026.8.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw