CVE-2026-100594 UNKNOWN

CVE-2026-100594

Published: 2026-09-26

Description

OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool schemas, runtime events, and local path metadata from affected sessions by exploiting insufficient authorization checks.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…