Threat intelligence dashboard
CVE-2026-100562medium

OpenClaw before 2026.8.1 Authorization Bypass via sessions.create

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows operator.write callers to modify session configurations reserved for operator.admin scope. Attackers with write-scoped credentials can change existing session model, provider, thinking level, and auth-profile settings to redirect traffic and bypass administrative access controls.

Risk score

5.3

CVSS 4.0

Vendor
OpenClaw
Product
OpenClaw
CWE
CWE-863
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

OpenClaw

OpenClaw

Version / rangeStatusType
0 to before 2026.8.1affectedsemver
2026.8.1unaffectedsemver

Technical metrics

5.3

CVSS 4.0

Severity
medium
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

5.4

CVSS 3.1

Severity
medium
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N