OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100589

HIGH · CVSS 8.3 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

OpenClaw versions prior to 2026.7.1 are vulnerable to a sandbox bypass that permits unauthorized access to paired node browser actions, even when the allowHostControl setting is disabled. This flaw enables attackers controlling sandboxed agent input to manipulate the host browser, potentially compromising sensitive data and authenticated sessions. Organizations utilizing OpenClaw should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100589
Severity
HIGH
CVSS
8.3
EPSS
0.32%

Original NVD Description

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.