CVE-2026-100528EPSS p14.1%
CVE-2026-100528CVE-2026-100528
Description
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L |
| EPSS | 0.24% probability of exploitation · percentile 14.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |