CVE-2026-100534EPSS p16.8%
CVE-2026-100534CVE-2026-100534
Description
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
Scoring
| CVSS | 3.1 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 0.27% probability of exploitation · percentile 16.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |