PatchSiren cyber security CVE debrief
CVE-2026-100551 OpenClaw CVE debrief
CVE-2026-100551 debrief based on the supplied source corpus. OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI, potentially allowing an attacker to serve a replacement Control UI page and steal credentials. This issue is fixed in 2026.8.11. The vulnerability allows potential credential theft and operator access, including reading sensitive Gateway state and invoking host-capable tools. Defenders should assess exposure and prioritize remediation due to the critical nature of this vulnerability.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for OpenClaw for iOS deployments should assess exposure and prioritize remediation due to the critical nature of this vulnerability. This includes operators, security teams, and vulnerability management teams. They should verify OpenClaw for iOS version and review Gateway TLS pinning enforcement in Control UI.
Why it matters
Defenders should prioritize verifying and remediating OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 due to a critical vulnerability allowing potential credential theft and other impacts.
- Potential credential theft and operator access
- Possible reading of sensitive Gateway state
- Invocation of host-capable tools by an attacker
- Verification of Gateway TLS pinning enforcement in Control UI
Technical summary
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI, potentially allowing an attacker to serve a replacement Control UI page and steal credentials. This issue allows potential credential theft and operator access, including reading sensitive Gateway state and invoking host-capable tools. The vulnerability has a critical CVSS score of 9 and is fixed in 2026.8.11. Defenders should prioritize verifying and remediating OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 due to a critical vulnerability allowing potential credential theft.
Defensive priority
Defenders should prioritize verifying and remediating OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 due to a critical vulnerability allowing potential credential theft.
Recommended defensive actions
- Verify OpenClaw for iOS version and upgrade to 2026.8.11 if necessary
- Review and enforce Gateway TLS pinning in Control UI
- Monitor for suspicious activity related to OpenClaw for iOS
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source references provide details on the vulnerability in OpenClaw for iOS, including affected versions and potential impacts. Evidence is limited to CVE and NVD details. Defenders should verify OpenClaw for iOS version and review Gateway TLS pinning enforcement in Control UI. The vulnerability has a critical CVSS score of 9.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100551 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100551
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100551 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100551
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-jjpc-p3xf-8g7p
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-ios-control-ui-tls-pin-enforcement-bypass
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.