PT-2026-99191 · Openclaw · Openclaw

·

CVE-2026-100554

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.5.12 through 2026.8.0
Description When a paired node is revoked, the system fails to immediately invalidate Canvas HTTP authorization. While the WebSocket client is invalidated, the Canvas HTTP authorization continues to accept and renew the previously granted capability until the WebSocket close cleanup process is finished. This allows a revoked paired node to continue using its Canvas capability against configured routes during the close grace period.
Recommendations Update to version 2026.8.1. As a temporary workaround, restart the Gateway after revoking a node that has Canvas access.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100554
GHSA-G697-VV6H-R8HV

Affected Products

Openclaw