Junglewise Threat Intelligence

CVE-2026-100604: ClawHub incorrect authorization in organization skill transfer

CVE-2026-100604 · Severity: medium · CVSS 5.4 · Published 2026-09-26

Technologies: Openclaw ClawHub. Vendors: Openclaw.

Executive brief

ClawHub is a platform for managing reusable code skills within organizations. A former employee or user who originally published an organization skill can still transfer, delete, or restore that skill after their access has been revoked, maintaining control over its trusted name and history. This allows unauthorized takeover of organization assets by individuals who no longer have the right to do so.

Technical details

The vulnerability is an incorrect authorization check (CWE-863) in the skill transfer and lifecycle endpoints. Organization-owned skills retain the ownerUserId of their original publisher, and authorization checks trust that historical user ID before validating current organization privileges. An authenticated former publisher can exploit this to transfer, delete, or restore skills even after organization role downgrade or revocation. The fix validates current organization privileges before allowing these operations.

Affected products

  • OpenClaw ClawHub prior to revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650

Timeline

  • 2026-09-11: disclosed: Fix deployed to clawhub.ai
  • 2026-09-11: patched: PR #3680 merged in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650
  • 2026-09-26: advisory: CVE-2026-100604 published

References

Related threats