CVE-2026-100588
Published 26 September 2026 · tracked since 26 September 2026
Description
OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narr
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-100876 MEDIUM 6.3
- CVE-2026-100875 HIGH 7.3
- CVE-2026-100873 MEDIUM 4.3
- CVE-2026-100874 HIGH 7.3
- CVE-2026-101060 HIGH 8.2
- CVE-2026-101061 MEDIUM 4.7
- CVE-2026-101047 MEDIUM 5.3
- CVE-2026-101057 LOW 3.1
- CVE-2026-101058 MEDIUM 6.9
- CVE-2026-101044 HIGH 7.1