PT-2026-99224 · Openclaw · Openclaw

·

CVE-2026-100588

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.7.1
Description The software fails to enforce the administrator scope requirement for browser control when accessed via the node.invoke method, despite direct browser.request access requiring such scope. In Gateway deployments that utilize caller identity and narrow operator scopes, a caller with write-scope access to a browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without administrator privileges. The actual impact depends on the browser profile and the current signed-in state. Callers using shared-secret tokens or passwords are not affected as they are treated as fully trusted operators.
Recommendations Update to version 2026.7.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100588
GHSA-JGHR-XP78-995P

Affected Products

Openclaw