CVE-2026-100535
Received Received - Intake

OpenClaw Session Memory Restriction Bypass

Vulnerability report for CVE-2026-100535, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sender whose messages are admitted with limited tools can persist instructions that are later supplied to an unattended background (dreaming) agent holding broader file and command capabilities, allowing actions beyond the authority of the original turn and affecting files, commands, or services available to that agent. Exploitation requires the content to be captured, selected for later processing, and followed by the model. The issue is fixed in 2026.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw versions between 2026.4.5 and below 2026.8.1 can lose the originating requester's restrictions when session-derived text is saved to session memory. This allows a restricted external sender to embed instructions that a later background model might execute with elevated authority. Exploitation requires the content to be captured, selected for later processing, and executed by the model.

Detection Guidance

To detect this vulnerability, check if your OpenClaw version is between 2026.4.5 and below 2026.8.1. Run: npm list openclaw. If the version is vulnerable, update to 2026.8.1 or later. Also verify if session-memory capture and dreaming features are enabled in your configuration.

Impact Analysis

This vulnerability could allow a restricted external sender to perform actions beyond their original permissions. These actions might affect files, commands, or services available to the background agent. Successful exploitation requires specific conditions like session-memory capture and dreaming being enabled.

Compliance Impact

This vulnerability could lead to unauthorized access or actions affecting files, commands, or services, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information security) if sensitive data is exposed or altered. The loss of requester restrictions may result in unauthorized processing or disclosure of personal or protected health information.

Mitigation Strategies

Immediately upgrade OpenClaw to version 2026.8.1 or later. Alternatively, disable dreaming for agents accepting restricted external senders, disable session-memory capture, or run background memory processing without mutation and command tools until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100535. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart