CVE-2026-59261: OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.5.28 - Compensating control
Ensure attackers do not have lower-trust access to configured input paths that allow modification of workspace dotenv files, so provider credentials cannot be overridden via those dotenv files.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59261?
CVE-2026-59261 has a severity rating of 8.4, which is classified as high.
How do I fix CVE-2026-59261?
To resolve CVE-2026-59261, upgrade OpenClaw to version 2026.5.28 or later.
What vulnerability does CVE-2026-59261 describe?
CVE-2026-59261 describes a credential exposure vulnerability that allows workspace dotenv files to override provider credentials.
Who is impacted by CVE-2026-59261?
Users of OpenClaw versions prior to 2026.5.28 are at risk due to this vulnerability.
What can attackers do with CVE-2026-59261?
Attackers with low-trust access can exploit this vulnerability to expose sensitive data and credentials.