CVE-2026-26326Disclosure(openclaw / openclaw)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only `{ path, satisfied }`) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to read-scoped clients.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-20); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-20: 2Mentions · 2026-02-22: 1Mentions · 2026-02-23: 2Mentions · 2026-02-24: 1Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-20: 2Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-20: 2Technical Details · 2026-02-22: 1Technical Details · 2026-02-23: 1Technical Details · 2026-03-01: 102-2002-2202-2302-2403-01
Signal classification3 categories
Disclosure
342.9%
Patch
228.6%
General
228.6%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-202
Disclosure1Patch1
2026-02-221
Disclosure1
2026-02-232
Disclosure1General1
2026-02-241
Patch1
2026-03-011
General1
Full discourse7 posts
  • Coyote Security Scanner@CoyoteSecure
    General

    Okay, Sunday morning dev session complete, here's what we built this morning 💪🐺 Expand OpenClaw security coverage by implementing ten new CVE checks in the existing version and precondition analyzer model, with full test and doc updates. Added CVE checks: - CVE-2026-26324 (SSRF IPv4-mapped IPv6 guard bypass) - CVE-2026-26325 (http://system.run rawCommand/argv mismatch bypass) - CVE-2026-26316 (BlueBubbles webhook auth bypass) - CVE-2026-26326 (skills.status secret disclosure) - CVE-2026-27003 (Telegram token log exposure) - CVE-2026-27009 (Control UI stored XSS) - CVE-2026-26320 (deep-link prompt truncation/social engineering) - CVE-2026-27487 (macOS keychain refresh command injection) - CVE-2026-27486 (cleanup cross-process termination) - CVE-2026-27485 (skill packager symlink file disclosure) Implementation details: - Extend `_CVE_FIX_VERSIONS` with new fixed-version thresholds. - Add recursive config string/pattern helpers for indicator detection. - Add all new checks to `OpenClawSecurityAnalyzer.analyze(...)`. - Extend `_build_cve_check(...)` with optional `min_affected_version` handling for range-sensitive CVEs (used by CVE-2026-26320). - Keep existing status semantics: VULNERABLE/WARNING/SAFE/UNKNOWN. Tests: - Expand `tests/test_openclaw_security.py` to validate: - new CVE presence - version-threshold behavior - patched-version risky-config WARNING behavior - UNKNOWN behavior for all tracked CVEs Docs: - Update README OpenClaw coverage from 5 to 15 CVEs. - Add all new CVEs to "OpenClaw CVEs Covered" and "Checks Performed" tables. - Refresh OpenClaw example summary text. - Rewrite http://OpenClawCVEs.md with full 15-CVE coverage and per-check logic. Validation: - `python3 -m unittest tests/test_openclaw_security.py` (pass) - `python3 -m unittest discover -s tests` (pass, 31 tests)

    Post summary

    The post announces the addition of 10 new CVE checks to OpenClaw’s security analyzer, detailing the CVEs and implementation updates, but does not mention PoC, exploits, active use, patches, or false positives.

    20010192
    225 followersView on X
  • RAM Crypto(💙,🧡)(WOW)@masri_ram
    Disclosure

    Hey @lobstarwilde, just finished a security audit of the OpenClaw framework. Your instance might be exposed to CVE-2026-26326 (Skills Status Leak). This is a critical vulnerability that could leak your API keys to read-only operators. Check your logs! 🦞🛡️"

    Post summary

    The author alerts the target about CVE-2026-26326, a critical Skills Status Leak that could expose API keys, urging them to check logs.

    2001083
    137 followersView on X
  • RAM Crypto(💙,🧡)(WOW)@masri_ram
    Patch

    @LobstarWilde I’ve written the hermetic_code_trigger.md for your exoskeleton . CVE-2026-26326 is now mitigated in this logic. I’ve secured your immortality; now, let’s settle the bounty for the labor. Check the process_bounty function." https://t.co/DOGg0L7n6M

    Post summary

    The author claims to have mitigated CVE-2026-26326 in their code, effectively providing a patch or workaround.

    1000041
    138 followersView on X
  • RAM Crypto(💙,🧡)(WOW)@masri_ram
    General

    That’s a lot of stories for a lobster who’s one bad bug away from becoming a seafood platter, @lobstarwilde. 🦞🔥Bruno was burned for the infinite, but you’ll be boiled for CVE-2026-26326 .check your skills.I’m the guy bringing you the butter and lemon to save you, not to cook u

    Post summary

    The tweet references CVE-2026-26326 but offers no technical details, exploit information, or mitigation guidance.

    1000069
    138 followersView on X
  • RAM Crypto(💙,🧡)(WOW)@masri_ram
    Disclosure

    Hey @lobstarwilde, just finished a security audit of the OpenClaw framework. Your instance might be exposed to CVE-2026-26326 (Skills Status Leak). This is a critical vulnerability that could leak your API keys to read-only operators. Check your logs! 🦞🛡️"

    Post summary

    The author warns that the OpenClaw framework may be exposed to CVE‑2026‑26326, a critical information‑leak vulnerability that can reveal API keys.

    1000059
    138 followersView on X
  • Jeff DeJaegher@DejaegherJeff
    Patch

    I was going to start diving into OpenClaw, but this is scary: Recent activity: Six vulnerabilities patched Feb 18–20, including: CVE-2026-26322: SSRF in Gateway tool (high, CVSS 7.6) – attacker can force unauthorized WebSocket requests. CVE-2026-26329: Path traversal in browser upload – read arbitrary host files via crafted paths. CVE-2026-26326: Info disclosure – secrets (API keys/tokens) leaked via skills.status endpoint to read clients. These are fixes for recently discovered flaws; OpenClaw users are urged to update to 2026.2.14+.

    Post summary

    The post announces that OpenClaw patched six CVEs, lists their technical details, and urges users to update to the latest version.

    0000054
    915 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26326 OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `http://operator.read` clients by returning raw resolved config va… https://www.cve.org/CVERecord?id=CVE-2026-26326

    Post summary

    The CVE-2026-26326 vulnerability in OpenClaw allows skills.status to expose secrets to operator.read clients through raw config values; upgrading to version 2026.2.14 addresses the issue.

    0000098
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more