2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100559 | HIGH | 8 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist p... |
| CVE-2026-100558 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauth... |
| CVE-2026-100557 | HIGH | 8.3 | 0.2% | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to car... |
| CVE-2026-100556 | MEDIUM | 6.3 | — | Sep 26, 2026 | OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in ... |
| CVE-2026-100555 | HIGH | 7.1 | — | Sep 26, 2026 | OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment del... |
| CVE-2026-100554 | MEDIUM | 4.2 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authori... |
| CVE-2026-100553 | MEDIUM | 4.3 | 0.2% | Sep 26, 2026 | OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feis... |
| CVE-2026-100552 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server... |
| CVE-2026-100551 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While nat... |
| CVE-2026-100550 | MEDIUM | 5.4 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. ... |
| CVE-2026-100549 | MEDIUM | 5.4 | 0.3% | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filena... |
| CVE-2026-100548 | MEDIUM | 5.3 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory emb... |
| CVE-2026-100547 | MEDIUM | 5.5 | — | Sep 26, 2026 | OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), ... |
| CVE-2026-100546 | MEDIUM | 6.4 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime v... |
| CVE-2026-100545 | MEDIUM | 5.3 | 0.2% | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filena... |
| CVE-2026-100544 | HIGH | 8.8 | — | Sep 26, 2026 | openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls wi... |
| CVE-2026-100543 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacte... |
| CVE-2026-100542 | LOW | 3.1 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill i... |
| CVE-2026-100541 | HIGH | 7.5 | 0.3% | Sep 26, 2026 | OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matr... |
| CVE-2026-100540 | MEDIUM | 6.8 | — | Sep 26, 2026 | OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it f... |
| CVE-2026-100539 | LOW | 2.6 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memor... |
| CVE-2026-100538 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySen... |
| CVE-2026-100537 | LOW | 3.1 | 0.2% | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy durin... |
| CVE-2026-100536 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attacke... |
| CVE-2026-100535 | HIGH | 7.5 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now