2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100592MEDIUM6.3OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mu...
CVE-2026-100591MEDIUM6.3OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations cou...
CVE-2026-100590MEDIUM4.3OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner ...
CVE-2026-100589HIGH8.3OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessi...
CVE-2026-100588HIGH8.3OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser contro...
CVE-2026-100587HIGH8.8OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation c...
CVE-2026-100586HIGH8.8OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings....
CVE-2026-100585HIGH8OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C...
CVE-2026-100584MEDIUM6.7OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Wi...
CVE-2026-100583MEDIUM4.3OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions t...
CVE-2026-100582MEDIUM6.5OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8...
CVE-2026-100581MEDIUM5.5OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the ...
CVE-2026-100580HIGH8.8OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a m...
CVE-2026-100579HIGH7.6OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity...
CVE-2026-100578HIGH7.6OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the ...
CVE-2026-100577MEDIUM6.3OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests...
CVE-2026-100576MEDIUM5.4OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that al...
CVE-2026-100575HIGH8.8OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disa...
CVE-2026-100574MEDIUM5.9OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-ho...
CVE-2026-100573LOW3.3OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allow...
CVE-2026-100572MEDIUM5.3OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authen...
CVE-2026-100571MEDIUM5.3OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit b...
CVE-2026-100570HIGH7.8OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the...
CVE-2026-100569MEDIUM5.5OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable ...
CVE-2026-100568HIGH8.3OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now