Junglewise Threat Intelligence

CVE-2026-26326: OpenClaw skills.status information disclosure

CVE-2026-26326 · Severity: medium · CVSS 4 · Published 2026-02-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular open-source framework used to orchestrate and manage skills and integrations. A vulnerability in the skills.status method allows users with read-only access to retrieve sensitive configuration secrets—such as Discord bot tokens—that should only be accessible to administrators. An attacker with read-only credentials could gain full access to critical credentials without triggering elevated privilege requirements.

Technical details

The vulnerability is an information disclosure (CWE-200) in OpenClaw's skills.status gateway method. The method returns resolved configuration values in configChecks[].value, including raw secrets for any config subtree required by a skill (e.g., channels.discord). Because skills.status is callable by users with the operator.read role, attackers can extract credentials without needing operator.admin or config.* permissions. The attack requires network access and a valid read-scoped credential, but no additional user interaction. The fix removes raw resolved values from the output and narrows skill requirements to specific keys rather than entire config subtrees. Patches are available in OpenClaw version 2026.2.14 and later.

Affected products

  • OpenClaw openclaw <= 2026.2.13

Timeline

  • 2026-02-17: disclosed: Advisory published
  • 2026-02-14: patched: Fix version 2026.2.14 released

References

Related threats