CVE-2026-100595: OpenClaw before 2026.7.1 Authorization Bypass via diagnostics
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. Attackers can request and receive diagnostic details about the host, configuration, runtime, and connected services intended only for owners.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.7.1
Event History
Frequently Asked Questions
Who can exploit this issue?
A non-owner channel sender can exploit the issue. The attacker needs the ability to send requests in a channel; no user interaction is required.
What information could be exposed?
The diagnostics export command can return owner-only host diagnostic bundles. These may include details about the host, configuration, runtime, and connected services.
Are affected installations vulnerable by default?
The available information does not state whether the diagnostics export command is enabled or reachable in the default configuration.
How can I determine whether my deployment is affected?
Deployments running an OpenClaw version before 2026.7.1 are affected. Review whether non-owner channel senders can invoke the diagnostics export command and receive diagnostic bundle contents.