CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100525

MEDIUMCVSS 4.3NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective r

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100525 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100525

MEDIUMCVSS 4.3NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective r

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]