CVE-2026-100581
Received Received - Intake

OpenClaw iOS App Stores Gateway Credentials in Cleartext

Vulnerability report for CVE-2026-100581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.8.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. This means sensitive tokens and passwords are saved in an unencrypted format outside the secure Keychain storage. Attackers with access to unencrypted device backups or extracted App Group containers can recover these credentials to gain operator-level access.

Detection Guidance

To detect this vulnerability, inspect the App Group UserDefaults storage on iOS devices running OpenClaw versions prior to 2026.8.11. Check for cleartext JSON files containing Gateway credentials. Use forensic tools to extract App Group containers from backups or jailbroken devices and search for sensitive data in plaintext.

Impact Analysis

If you use OpenClaw iOS versions before 2026.8.11, an attacker could recover your Gateway credentials from unencrypted backups or device images. This could allow them to authenticate with operator authority, potentially accessing sensitive systems or data. The risk is higher if you use unencrypted backups or if your device is compromised.

Compliance Impact

This vulnerability likely violates compliance requirements for protecting sensitive data, such as GDPR and HIPAA, due to cleartext storage of credentials. GDPR mandates strong protection for personal data, while HIPAA requires safeguarding protected health information. Storing credentials insecurely could lead to unauthorized access and data breaches, resulting in legal and regulatory penalties.

Mitigation Strategies

Upgrade OpenClaw for iOS to version 2026.8.11 or later. Avoid creating unencrypted device backups. If backups or device images may have been exposed, rotate Gateway credentials immediately to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart