PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100539 OpenClaw CVE debrief

OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at creation time because the execution-time resolver treats explicit disablement like an unavailable configuration snapshot and restores the stale authority. As a result, during an already-running agent turn the model can continue searching and reading durable memory after the operator revoked that access, for the remainder of that run. Exploitation requires memory to be disabled while a previously created memory tool remains active. The issue is fixed in 2026.8.1.

Vendor
OpenClaw
Product
Unknown
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders who use OpenClaw (npm package 'openclaw') before 2026.8.1 should assess their exposure and consider upgrading to 2026.8.1 or later to address the issue. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify their OpenClaw version and take appropriate actions to mitigate the vulnerability.

Why it matters

The CVE-2026-100539 vulnerability in OpenClaw (npm package 'openclaw') before 2026.8.1 allows the model to continue searching and reading durable memory after the operator revoked that access. Defenders should prioritize verifying their OpenClaw version and consider upgrading to 2026.8.1 or later.

  • Defenders need to verify if their OpenClaw version is before 2026.8.1 and consider upgrading to address the issue.
  • The vulnerability allows the model to continue searching and reading durable memory after the operator revoked that access, for the remainder of that run.
  • Exploitation requires memory to be disabled while a previously created memory tool remains active.

Technical summary

The OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memory configuration. Existing memory_search and memory_get tool instances retain the enabled configuration captured at creation time because the execution-time resolver treats explicit disablement like an unavailable configuration snapshot and restores the stale authority. This issue allows the model to continue searching and reading durable memory after the operator revoked that access, for the remainder of that run. Exploitation requires memory to be disabled while a previously created memory tool remains active.

Defensive priority

Defenders should prioritize verifying if their OpenClaw version is before 2026.8.1 and consider upgrading to 2026.8.1 or later to address the issue.

Recommended defensive actions

  • Verify if the OpenClaw version is before 2026.8.1
  • Consider upgrading to 2026.8.1 or later
  • Review and update configurations for memory tool access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide information about the vulnerability in OpenClaw. The issue is related to the package's failure to revoke memory tool access when an operator hot-disables memory configuration.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100539 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100539

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100539 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100539

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.