CVE-2026-100525
Last modified
CVE-2026-100525 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read scope can retrieve the diagnostics document even though ordinary read methods reject the same identity, disclosing operational metrics to an authenticated profile intentionally limited below read access.
Description
The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read scope can retrieve the diagnostics document even though ordinary read methods reject the same identity, disclosing operational metrics to an authenticated profile intentionally limited below read access. Shared-secret Gateway callers already hold the documented full operator scope and are not affected. The issue is fixed in 2026.9.3; as a workaround, disable the Prometheus endpoint or ensure every identity that can reach it is intended to hold operator.read.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openclaw | diagnostics-prometheus | < 2026.9.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100525?
How severe is CVE-2026-100525?
How do I fix CVE-2026-100525?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10052A flaw was found in the Quay config-tool's LDAP and SMTP val…4.1
- CVE-2026-100520Laranode versions before 1.2.1 contain a path traversal vuln…8.8
- CVE-2026-100521Cotonti through 1.0.0 contains a reflected cross-site script…6.1
- CVE-2026-100522Cotonti through 1.0.0 contains a reflected cross-site script…6.1
- CVE-2026-100523Cotonti through 1.0.0 contains an open redirect vulnerabilit…6.1
- CVE-2026-100524Cotonti through 1.0.0 contains a cross-site request forgery …5.4
- CVE-2026-100526OpenClaw's Discord integration (npm package @openclaw/discor…5.3
- CVE-2026-100527OpenClaw before 2026.8.2 contains a denial of service vulner…5.3
- CVE-2026-100528OpenClaw (npm package 'openclaw') before 2026.8.1 could send…5.4
- CVE-2026-100529OpenClaw versions before 2026.8.1 contain an authorization s…6.4
- CVE-2026-10053GitLab has remediated an issue in GitLab CE/EE affecting all…8.8
- CVE-2026-100530OpenClaw versions before 2026.8.1 fail to bind working direc…7.3
Are you affected by CVE-2026-100525?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
