2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100567HIGH8.2OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gate...
CVE-2026-100566MEDIUM6.5OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inher...
CVE-2026-100564MEDIUM5.4OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within ...
CVE-2026-100563MEDIUM5.4OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications i...
CVE-2026-100562MEDIUM5.4OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that all...
CVE-2026-100561HIGH8OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec appro...
CVE-2026-100560HIGH7.5OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact c...
CVE-2026-100559HIGH8OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist p...
CVE-2026-100558HIGH7.5OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauth...
CVE-2026-100557HIGH8.3OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to car...
CVE-2026-100556MEDIUM6.3OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in ...
CVE-2026-100555HIGH7.1OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment del...
CVE-2026-100554MEDIUM4.2OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authori...
CVE-2026-100553MEDIUM4.3OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feis...
CVE-2026-100552HIGH8.8OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server...
CVE-2026-100551HIGH8.3OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While nat...
CVE-2026-100550MEDIUM5.4OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. ...
CVE-2026-100549MEDIUM5.4OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filena...
CVE-2026-100548MEDIUM5.3OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory emb...
CVE-2026-100547MEDIUM5.5OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), ...
CVE-2026-100546MEDIUM6.4OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime v...
CVE-2026-100545MEDIUM5.3OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filena...
CVE-2026-100544HIGH8.8openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls wi...
CVE-2026-100543HIGH7.5OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacte...
CVE-2026-100542LOW3.1OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now