PT-2026-99199 · Openclaw · Openclaw

·

CVE-2026-100562

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.8.1
Description An authorization bypass exists in the 'sessions.create' endpoint. This issue allows users with operator.write permissions to modify session configurations that should be restricted to the operator.admin scope. By manipulating the model, provider, thinking level, and auth-profile variables, an attacker can redirect traffic and circumvent administrative access controls.
Recommendations Update to version 2026.8.1 or later. Restrict the use of the 'sessions.create' endpoint for users with operator.write permissions until the update is applied.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100562
GHSA-J4MM-P864-VX7F

Affected Products

Openclaw