HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-100557 — OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability ...

·Source: NIST NVD

Updated:

Executive Summary

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.

Analysis

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners. CVSS Score: 8.3. Published: 2026-09-26T03:17:02.387.

Indicators of Compromise (1)

CVE (1)
CVE-2026-100557
Source Attribution

Originally published by NIST NVD on Sep 26, 2026. Verified by: NIST.

Related Threats