CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100588

HIGHCVSS 8.3NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narr

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100588 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100588

HIGHCVSS 8.3NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narr

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]