CVE-2026-100562: OpenClaw before 2026.8.1 Authorization Bypass via sessions.create
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and auth-profile settings to redirect traffic and bypass administrative access controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs credentials with the operator.write scope. No user interaction is required, and the vulnerable endpoint is reachable over the network.
What unauthorized changes can a write-scoped caller make?
They can modify configuration on existing sessions that should be reserved for operator.admin, including the model, provider, thinking level, and auth-profile settings. This can redirect traffic and bypass administrative access controls.
Which versions are affected and what is the remediation?
OpenClaw versions before 2026.8.1 are affected. Upgrade to version 2026.8.1 or later.