rootpwn

low · CVSS v3 3.1 · CVSS v4 2.3 · EPSS 0.00266

CVE-2026-100534

OpenClaw versions prior to 2026.8.1 have an authorization bypass in webhook TaskFlow cancellation. An attacker with a webhook route secret c

Overview

OpenClaw versions prior to 2026.8.1 have an authorization bypass in webhook TaskFlow cancellation. An attacker with a webhook route secret can cancel unrelated sessions, potentially disrupting ACP or subagent operations. This flaw can affect any deployment using the vulnerable OpenClaw webhook functionality.

Description

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.

Impact

Confidentiality impact is minimal; Integrity is compromised by unauthorized session cancellation; Availability may be affected by denial of critical tasks. Defenders such as system administrators and DevOps teams managing OpenClaw deployments are impacted.

Remediation

Apply the 2026.8.1 patch or later. If patch cannot be applied immediately, restrict webhook route secrets to only authorized users, enforce least privilege, and monitor for unexpected cancellation events. Additionally, disable or isolate the TaskFlow cancellation endpoint until a fix is deployed.

Risk context

The vulnerability has a low severity score (CVSS v3 3.1) and a very low EPSS of 0.00266, indicating a low likelihood of exploitation in the wild. Nevertheless, defenders should address it promptly to prevent potential disruption.

Affected products

  • OpenClaw

Scores

Severity
low
CVSS v2
2.1
CVSS v3
3.1
CVSS v4
2.3
EPSS
0.00266

authorization-bypass webhook session-cancellation OpenClaw low-severity defense patch

← All CVEs