CVE-2026-59261 HIGH

CVE-2026-59261: OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files

Vendor Openclaw
Product OpenClaw
Weakness CWE-184
Published July 8, 2026
Last update July 20, 2026

CVSS base score

8.4/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

Key dates

02Disclosure timeline

July 8, 2026 CVE published
July 20, 2026 Record updated