CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100551

HIGHCVSS 8.3NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attac

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100551 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100551

HIGHCVSS 8.3NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attac

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]