Impact
OpenClaw iOS versions prior to 2026.8.11 log complete deep‑link URLs, including persistent bearer keys, as public diagnostic data. The exposed tokens allow an attacker who obtains the diagnostic logs to replay the links and submit agent requests without local confirmation prompts, effectively granting unauthorized access to the application. This weakness is a data‑exposure vulnerability (CWE‑532) that compromises the confidentiality of authentication credentials.
Affected Systems
The affected product is OpenClaw iOS, specifically all releases before 2026.8.11. Users running version 2026.8.10 or earlier are impacted and must upgrade to a newer release that removes bearer keys from diagnostic logs.
Risk and Exploitability
The CVSS score of 7.2 classifies this as a high‑severity issue. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the wild to date. To exploit the flaw, an attacker must acquire the diagnostic archive—through backup theft, misconfigured backup services, or insider access—which is a non‑zero‑day vector requiring non‑trivial access. The lack of a publicly known exploit reduces immediate risk but does not eliminate the threat of credential misuse.
OpenCVE Enrichment