Impact
OpenClaw fails to revoke access to memory tools when an operator hot‑disables the memory configuration. A memory_search or memory_get instance that was created before the disable retains the enabled state because the runtime treats the explicit disable as a snapshot and restores a stale authority. Consequently, during an existing run the model can continue searching and reading durable memory after the operator has revoked that access, exposing data that should no longer be available. The flaw is a control‑flow weakness that allows unauthorized memory reads in the short window of an agent run.
Affected Systems
The vulnerability affects the OpenClaw npm package (openclaw) in all releases before version 2026.8.1. No additional vendor or product variations are listed.
Risk and Exploitability
The CVSS score of 2.1 indicates a low severity impact, and the EPSS score is not available, while the vulnerability is not listed in the CISA KEV catalog. Attacks would require an operator with the ability to disable memory configuration while a previously created memory tool remains active, and the effect is limited to the remainder of the current agent run. The limited scope and requirement for in‑place operator action suggest a low likelihood of exploitation in typical deployments.
OpenCVE Enrichment