CVE-2026-100534
LOW
NVD
CVSS Score
3.1
Severity
LOW
Published
Sep 26, 2026
Vendor
unknown
Description
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.