rootpwn

high · CVSS v3 8.3 · CVSS v4 8.7 · EPSS 0.00237

CVE-2026-100557

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to car…

Description

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry the sender's owner status. Non-owner senders authorized to invoke skill commands can access owner-only tools and server credentials reserved for owners.

Scores

Severity
high
CVSS v2
8.7
CVSS v3
8.3
CVSS v4
8.7
EPSS
0.00237

← All CVEs