CVE-2026-100551: OpenClaw iOS Control UI TLS Pin Enforcement Bypass

Published Sep 26, 2026
·
Updated

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.

Affected Software

1 affected component
OpenClaw OpenClaw for iOS>=2026.7.1<2026.8.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw for iOS to a version that resolves this vulnerability.

    Fixed in 2026.8.11

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users of OpenClaw for iOS versions 2026.7.1 through before 2026.8.11 are exposed if they use the authenticated Terminal or session Dashboard WebViews after accepting a Gateway fingerprint. Native connections continue to enforce the saved Gateway fingerprint.

2

What does an attacker need to exploit it?

An attacker must be able to redirect the same Gateway host and port to their own server and present a different certificate that iOS system trust accepts. The user must then open the Terminal or a session Dashboard, allowing the replacement Control UI page to access the injected Gateway token or password.

3

What could an attacker obtain or do with the stolen credential?

The replacement page can read the injected Gateway token or password. Those credentials can provide operator access, including access to sensitive Gateway state and the ability to invoke host-capable tools.

4

What is the remediation?

Update OpenClaw for iOS to version 2026.8.11, which fixes the missing TLS pin enforcement in the affected Control UI WebViews.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203