CVE-2026-100588: OpenClaw before 2026.7.1 Authentication Bypass via node.invoke

Published Sep 26, 2026
·
Updated

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without the configured admin requirement; practical impact depends on the browser profile and signed-in state. Shared-secret token and password callers are considered fully trusted operators under OpenClaw's security model and are not affected. The issue is fixed in 2026.7.1.

Affected Software

1 affected component
npm/openclaw<2026.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/openclaw to a version that resolves this vulnerability.

    Fixed in 2026.7.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are actually exposed to this issue?

Gateway deployments that honor caller identity and use narrower operator scopes are exposed when a write-scoped caller can access a connected browser-capable node. The practical impact depends on the browser profile and whether it is signed in to browser-visible applications.

2

What access does an attacker need?

An attacker needs a write-scoped caller identity and access to a connected node with browser capability. They can use node.invoke to reach browser control without the administrator scope required for direct browser.request access.

3

Are shared-secret token or password-based callers affected?

No. OpenClaw considers shared-secret token and password callers fully trusted operators, so they are not affected by this scope-enforcement bypass.

4

What can an unauthorized write-scoped caller do through the bypass?

They may inspect pages, navigate tabs, or interact with applications visible in the connected browser. Access to signed-in applications depends on the browser's existing profile and session state.

5

What version fixes the issue?

The issue is fixed in OpenClaw 2026.7.1. Versions before 2026.7.1 are affected under the applicable Gateway and caller-scope conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203