2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100585HIGH8OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C...
CVE-2026-100584MEDIUM6.7OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Wi...
CVE-2026-100583MEDIUM4.3OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions t...
CVE-2026-100582MEDIUM6.5OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8...
CVE-2026-100581MEDIUM5.5OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the ...
CVE-2026-100580HIGH8.8OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a m...
CVE-2026-100579HIGH7.6OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity...
CVE-2026-100578HIGH7.6OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the ...
CVE-2026-100577MEDIUM6.3OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests...
CVE-2026-100576MEDIUM5.4OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that al...
CVE-2026-100575HIGH8.8OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disa...
CVE-2026-100574MEDIUM5.9OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-ho...
CVE-2026-100573LOW3.3OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allow...
CVE-2026-100572MEDIUM5.3OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authen...
CVE-2026-100571MEDIUM5.3OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit b...
CVE-2026-100570HIGH7.8OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the...
CVE-2026-100569MEDIUM5.5OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable ...
CVE-2026-100568HIGH8.3OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible...
CVE-2026-100567HIGH8.2OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gate...
CVE-2026-100566MEDIUM6.5OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inher...
CVE-2026-100564MEDIUM5.4OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within ...
CVE-2026-100563MEDIUM5.4OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications i...
CVE-2026-100562MEDIUM5.4OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that all...
CVE-2026-100561HIGH8OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec appro...
CVE-2026-100560HIGH7.5OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now