CVE-2026-100535: OpenClaw before 2026.8.1 Privilege Escalation via Session Memory

Published Sep 26, 2026
·
Updated

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to an unattended background (dreaming) agent holding broader file and command capabilities, allowing actions beyond the authority of the original turn and affecting files, commands, or services available to that agent. Exploitation requires the content to be captured, selected for later processing, and followed by the model. The issue is fixed in 2026.8.1.

Affected Software

1 affected component
npm/openclaw>=2026.4.5<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade openclaw to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Affected deployments use OpenClaw versions from 2026.4.5 through versions before 2026.8.1, and have both session-memory capture and dreaming enabled. The meaningful exposure is where restricted external senders can submit messages and the unattended dreaming agent has broader file or command capabilities.

2

What must happen for exploitation to succeed?

An external sender's content must be captured into session memory, selected for later dreaming processing, and followed by the model. The attacker needs access as a restricted sender; the advisory does not describe exploitation by an entirely unauthenticated party.

3

What can an attacker do if exploitation succeeds?

The background dreaming agent can perform actions beyond the authority of the original restricted request. Impact is limited by the files, commands, and services available to that background agent, but can include effects on all three.

4

What should be done if upgrading cannot happen immediately?

Disable session-memory capture or dreaming to remove the described path between restricted sender content and the higher-privileged background agent. Also avoid allowing restricted external sender content to be persisted for later processing by an agent with broader capabilities.

5

How can I determine whether I am affected?

Check whether the installed npm openclaw version is at least 2026.4.5 and earlier than 2026.8.1. Then verify whether session-memory capture and dreaming are enabled and whether the dreaming agent has more file, command, or service access than external senders.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203