Description
OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts.
Published: 2026-09-22
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Credential Exposure
Action: Apply Patch
AI Analysis

Impact

OpenClaw iOS versions prior to 2026.8.11 log complete deep‑link URLs, including persistent bearer keys, as public diagnostic data. The exposed tokens allow an attacker who obtains the diagnostic logs to replay the links and submit agent requests without local confirmation prompts, effectively granting unauthorized access to the application. This weakness is a data‑exposure vulnerability (CWE‑532) that compromises the confidentiality of authentication credentials.

Affected Systems

The affected product is OpenClaw iOS, specifically all releases before 2026.8.11. Users running version 2026.8.10 or earlier are impacted and must upgrade to a newer release that removes bearer keys from diagnostic logs.

Risk and Exploitability

The CVSS score of 7.2 classifies this as a high‑severity issue. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the wild to date. To exploit the flaw, an attacker must acquire the diagnostic archive—through backup theft, misconfigured backup services, or insider access—which is a non‑zero‑day vector requiring non‑trivial access. The lack of a publicly known exploit reduces immediate risk but does not eliminate the threat of credential misuse.

Generated by OpenCVE AI on September 22, 2026 at 21:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the OpenClaw iOS application to version 2026.8.11 or later, where deep‑link URLs no longer contain persistent bearer keys in logs.
  • Configure the application to sanitize or remove sensitive information from all diagnostic logs, ensuring bearer keys are not recorded.
  • Implement strict access controls and monitoring on diagnostic archives to detect and prevent unauthorized retrieval of log data.

Generated by OpenCVE AI on September 22, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts.
Title OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-532
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T20:21:15.030Z

Reserved: 2026-09-22T15:47:14.339Z

Link: CVE-2026-95815

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T21:17:34.583

Modified: 2026-09-22T21:17:34.583

Link: CVE-2026-95815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:30:20Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File