CVE-2026-100543
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 08:14
Descrizione
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config.get) could test password candidates offline without going through the rate-limited Gateway authentication path. Recovering the password could grant the documented shared-secret operator authority. Secret references were not affected in the same way. The issue is fixed in 2026.8.1.
Alias e classificazioni
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
- cvss score
- 7.5
- cvss vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- cvss severity
- HIGH
Riferimenti pubblici
- VulnCheck Advisory: OpenClaw before 2026.8.1 Information Disclosure via Configuration Hash
https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-information-disclosure-via-configuration-hash - GitHub Security Advisory (GHSA-qgj5-6x35-9g6f)
https://github.com/openclaw/openclaw/security/advisories/GHSA-qgj5-6x35-9g6f
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.