PT-2026-99205 · Openclaw · Openclaw
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.25 through 2026.8.0
Description
The workspace environment-variable filter fails to block variables ending in
ENDPOINT. This allows an untrusted workspace .env file to set the AZURE SPEECH ENDPOINT variable. Because Azure Speech prioritizes this value over the configured region, requests for synthesis or voice-lists send the operator's Azure Speech key in the request header to an attacker-selected endpoint. This enables the attacker to reuse the key against the operator's Azure Speech resource. Exploitation occurs when an operator starts the application in attacker-controlled workspace content while Azure Speech is configured with a key and region, and no trusted endpoint override is set.Recommendations
Update OpenClaw to version 2026.8.1.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw