LOW 2.3 NVD
CVE-2026-100534
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessi
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-g24w-m94m-59qc
- https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-session-cancellation-authori
This low severity vulnerability with a CVSS score of 2.3 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11591 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.