Low severity3.1NVD Advisory· Published Sep 26, 2026
CVE-2026-100534
CVE-2026-100534
Description
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.