CVE-2026-100569: OpenClaw before 2026.8.1 Credential Exposure via Endpoint Override

Published Sep 26, 2026
·
Updated

OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in ENDPOINT, so an untrusted workspace .env file could set AZURESPEECHENDPOINT. Azure Speech preferred that value over the configured region, so when a synthesis or voice-list request was made, the attacker-selected endpoint received the operator's Azure Speech key in the request header, allowing the key to be reused against the operator's Azure Speech resource. Exploitation requires an operator to start OpenClaw in attacker-controlled workspace content with Azure Speech configured with a key and region and no trusted endpoint override set. The issue is fixed in 2026.8.1.

Affected Software

1 affected component
npm/openclaw>=2026.4.25<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to credential theft?

OpenClaw versions from 2026.4.25 through before 2026.8.1 are exposed when an operator starts the application in attacker-controlled workspace content, Azure Speech is configured with both a key and region, and no trusted endpoint override is set.

2

What interaction is required for exploitation?

An attacker needs to provide workspace content containing an untrusted .env file. The operator must start OpenClaw in that workspace, and a subsequent Azure Speech synthesis or voice-list request causes the Azure Speech key to be sent to the attacker-selected endpoint.

3

What can be done if upgrading is not immediately possible?

Do not start affected OpenClaw versions in untrusted or attacker-controlled workspaces. Ensure untrusted workspace .env files cannot set Azure Speech endpoint configuration; a trusted endpoint override prevents the described condition.

4

How can an operator determine whether a key may have been exposed?

Review whether an affected version was run in attacker-controlled workspace content with Azure Speech configured by key and region, without a trusted endpoint override. If so, Azure Speech synthesis or voice-list requests may have sent the key to an attacker-selected endpoint, and the key should be treated as exposed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203