Threat intelligence dashboard
CVE-2026-100534low

OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.

Risk score

2.3

CVSS 4.0

Vendor
OpenClaw
Product
OpenClaw
CWE
CWE-639
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

OpenClaw

OpenClaw

Version / rangeStatusType
0 to before 2026.8.1affectedsemver
2026.8.1unaffectedsemver

Technical metrics

2.3

CVSS 4.0

Severity
low
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

3.1

CVSS 3.1

Severity
low
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L