PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100527 OpenClaw CVE debrief

CVE-2026-100527 is a denial of service vulnerability in OpenClaw before 2026.8.2 that allows unauthenticated network sources to exhaust pending-authentication capacity. The vulnerability is in the Browser extension relay and allows attackers to hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2.

Vendor
OpenClaw
Product
Unknown
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders and administrators of OpenClaw systems should assess exposure and prioritize patching to prevent potential denial of service attacks. This includes reviewing system configurations, verifying patch application, and ensuring that incident response plans are updated to address this vulnerability.

Why it matters

CVE-2026-100527 is a denial of service vulnerability in OpenClaw before 2026.8.2 that allows unauthenticated network sources to exhaust pending-authentication capacity. Defenders should prioritize verifying and applying the patch to prevent potential denial of service attacks.

  • Denial of service attacks may occur if the patch is not applied
  • Defenders should verify and apply the patch to prevent potential attacks
  • Incident response plans should be reviewed and updated to address this vulnerability

Technical summary

The vulnerability is in the Browser extension relay of OpenClaw before 2026.8.2 and allows unauthenticated network sources to exhaust pending-authentication capacity. Attackers can hold every pending slot by maintaining silent WebSocket upgrades, preventing paired extensions from completing Browser Relay Authentication v2. This affects OpenClaw deployments that rely on Browser extension relay for authentication. Defenders should prioritize verifying and applying the patch to prevent potential denial of service attacks.

Defensive priority

Defenders should prioritize verifying and applying the patch to prevent potential denial of service attacks.

Recommended defensive actions

  • Verify and apply the patch to OpenClaw
  • Monitor for potential denial of service attacks
  • Review and update incident response plans
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is limited. OpenClaw systems should be reviewed for exposure, and defenders should verify and apply the patch to prevent potential denial of service attacks. Evidence is limited to CVE and NVD entries, and further verification is required.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100527 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100527

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100527 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100527

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.