CVE-2026-100594: OpenClaw before 2026.7.1 Authorization Bypass via trajectory export
Published Sep 26, 2026
·Updated
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool schemas, runtime events, and local path metadata from affected sessions by exploiting insufficient authorization checks.
Affected Software
1 affected component
OpenClaw<2026.7.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.7.1
Event History
Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require user interaction?
No. The CVSS vector indicates no user interaction is required.
2
What level of access does an attacker need?
The CVSS vector indicates that low privileges are required. The affected endpoint can be abused by a non-owner sender.