CVE-2026-100534Low· 3.1▾ SunlitOpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child se…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100579High· 7.6OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action
CVE-2026-32976Medium· 6.5OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions
GHSA-8wmm-344f-mpjgMedium· 7.1Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
CVE-2026-100599High· 8.8OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands
CVE-2026-100598High· 7.1OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions
CVE-2026-100597High· 7.8OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations