PT-2026-99191 · Openclaw · Openclaw
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.5.12 through 2026.8.0
Description
When a paired node is revoked, the system fails to immediately invalidate Canvas HTTP authorization. While the WebSocket client is invalidated, the Canvas HTTP authorization continues to accept and renew the previously granted capability until the WebSocket close cleanup process is finished. This allows a revoked paired node to continue using its Canvas capability against configured routes during the close grace period.
Recommendations
Update to version 2026.8.1.
As a temporary workaround, restart the Gateway after revoking a node that has Canvas access.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw