CVE-2026-100534: Openclaw
Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
Affected products
- Openclaw Openclaw: before 2026.8.1 (fixed in 2026.8.1)
Published 2026-09-26. Last modified 2026-09-28.