PT-2026-99185 · Openclaw · Openclaw
CVE-2026-100548
·
Published
2026-09-26
·
Updated
2026-09-30
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.3.28 through 2026.8.0
Description
A credential exposure issue exists in the memory embedding failover mechanism. When remote embedding fallback is configured and the primary embedding provider fails, the system may send the request to a fallback provider while reusing the primary provider's API key. This results in the credential being transmitted as a bearer token to an unintended vendor. The impact depends on the configured providers, whether failover occurs, and the privileges associated with the primary provider key.
Recommendations
Update to version 2026.8.1.
Disable cross-provider embedding fallback.
Configure each provider with separate, narrowly scoped credentials.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw