low · CVSS v3 3.1 · CVSS v4 2.3 · EPSS 0.00266
CVE-2026-100534
OpenClaw versions prior to 2026.8.1 have an authorization bypass in webhook TaskFlow cancellation. An attacker with a webhook route secret c
Overview
OpenClaw versions prior to 2026.8.1 have an authorization bypass in webhook TaskFlow cancellation. An attacker with a webhook route secret can cancel unrelated sessions, potentially disrupting ACP or subagent operations. This flaw can affect any deployment using the vulnerable OpenClaw webhook functionality.
Description
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
Impact
Confidentiality impact is minimal; Integrity is compromised by unauthorized session cancellation; Availability may be affected by denial of critical tasks. Defenders such as system administrators and DevOps teams managing OpenClaw deployments are impacted.
Remediation
Apply the 2026.8.1 patch or later. If patch cannot be applied immediately, restrict webhook route secrets to only authorized users, enforce least privilege, and monitor for unexpected cancellation events. Additionally, disable or isolate the TaskFlow cancellation endpoint until a fix is deployed.
Risk context
The vulnerability has a low severity score (CVSS v3 3.1) and a very low EPSS of 0.00266, indicating a low likelihood of exploitation in the wild. Nevertheless, defenders should address it promptly to prevent potential disruption.
Affected products
- OpenClaw
Scores
- Severity
- low
- CVSS v2
- 2.1
- CVSS v3
- 3.1
- CVSS v4
- 2.3
- EPSS
- 0.00266