OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100551

HIGH · CVSS 8.3 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

OpenClaw for iOS versions 2026.7.1 to 2026.8.10 fails to enforce TLS pinning in its Control UI, exposing users to potential credential theft through man-in-the-middle attacks. An attacker could exploit this vulnerability to redirect users to a malicious page, allowing them to capture sensitive tokens or passwords that grant operator access to the system. Organizations using affected versions should prioritize updating to version 2026.8.11 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100551
Severity
HIGH
CVSS
8.3
EPSS
0.17%

Original NVD Description

OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.