Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
8.3
CVE-2026-100588PATCHED
openclaw · openclaw

OpenClaw before 2026.7.1 Authentication Bypass via node.invoke

Description

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without the configured admin requirement; practical impact depends on the browser profile and signed-in state. Shared-secret token and password callers are considered fully trusted operators under OpenClaw's security model and are not affected. The issue is fixed in 2026.7.1.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-jghr-xp78-995p(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-authentication-bypass-via-node-invoke(third-party-advisory)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-100588 | OpenClaw up to 2026.7.0 node.invoke privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.7.1
CWECWE-863
PublishedSep 26, 2026
Last enriched1d ago
Trending Score22
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-100604EXP
ClawHub Authentication Bypass via Former Publisher Skill Control
Trending: 47
HIGHCVE-2026-100599EXP
OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
Trending: 36
HIGHCVE-2026-100589
OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
Trending: 23
HIGHCVE-2026-100597
OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
Trending: 23
HIGHCVE-2026-100596
OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 26, 2026
Discovered by ZDM
Sep 26, 2026
Patch Available
Sep 26, 2026