PT-2026-99185 · Openclaw · Openclaw

CVE-2026-100548

·

Published

2026-09-26

·

Updated

2026-09-30

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.3.28 through 2026.8.0
Description A credential exposure issue exists in the memory embedding failover mechanism. When remote embedding fallback is configured and the primary embedding provider fails, the system may send the request to a fallback provider while reusing the primary provider's API key. This results in the credential being transmitted as a bearer token to an unintended vendor. The impact depends on the configured providers, whether failover occurs, and the privileges associated with the primary provider key.
Recommendations Update to version 2026.8.1. Disable cross-provider embedding fallback. Configure each provider with separate, narrowly scoped credentials.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100548
GHSA-66HM-HXQ3-5PFH

Affected Products

Openclaw