CVE-2026-100588

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without the configured admin requirement; practical impact depends on the browser profile and signed-in state. Shared-secret token and password callers are considered fully trusted operators under OpenClaw's security model and are not affected. The issue is fixed in 2026.7.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🚨 OpenClaw’da 4 yeni High seviye güvenlik açığı OpenClaw'ın 2026.7.1 öncesi sürümlerini etkileyen 4 yeni CVE yayınlandı: 🔸 CVE-2026-100599 | CVSS 8.8 Google Meet node komutları üzerinden approval mekanizmasının bypass edilmesi ve bağlı node üzerinde kod çalıştırılması (RCE). 🔸 CVE-2026-100596 | CVSS 8.8 MCP yapılandırması üzerinden authorization bypass. Kötü amaçlı stdio komutu yapılandırmaya eklenerek kalıcı kod çalıştırma mümkün olabiliyor. 🔸 CVE-2026-100588 | CVSS 8.3 node.invoke üzerinden yetkilendirme kontrolünün aşılması ve bağlı browser node üzerinde yetkisiz işlemler gerçekleştirilmesi. 🔸 CVE-2026-100589 | CVSS 8.8 Sandbox kısıtlamalarının browser üzerinden aşılmasıyla host browser/node kontrolüne erişim sağlanabilmesi. 🛡️ Etkilenen sürümler: OpenClaw < 2026.7.1 ✅ Çözüm: OpenClaw 2026.7.1 veya üzeri sürüme güncelleyin. Özellikle CVE-2026-100599 ve CVE-2026-100596, agent'ın yetkileri üzerinden host üzerinde kod çalıştırma açısından dikkat çekiyor.

    00031405
    2.4K followersView on X

Explore more