目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2026-27004— OpenClaw 访问控制错误漏洞

EPSS 0.00% · P0
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-27004の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
ソース: NVD (National Vulnerability Database)
脆弱性説明
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (`sessions_list`, `sessions_history`, `sessions_send`) allowed broader session targeting than some operators intended. This is primarily a configuration/visibility-scoping issue in multi-user environments where peers are not equally trusted. In Telegram webhook mode, monitor startup also did not fall back to per-account `webhookSecret` when only the account-level secret was configured. In shared-agent, multi-user, less-trusted environments: session-tool access could expose transcript content across peer sessions. In single-agent or trusted environments, practical impact is limited. In Telegram webhook mode, account-level secret wiring could be missed unless an explicit monitor webhook secret override was provided. Version 2026.2.15 fixes the issue.
ソース: NVD (National Vulnerability Database)
CVSS情報
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
通过错误消息导致的信息暴露
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
OpenClaw 访问控制错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
OpenClaw是openclaw开源的一个智能人工助理。 OpenClaw 2026.2.15之前版本存在访问控制错误漏洞,该漏洞源于会话工具访问控制不当,可能导致多用户环境中会话内容泄露。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
openclawopenclaw < 2026.2.15 -

II. CVE-2026-27004の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-27004のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · openclaw · 2026-02-19 · 22 CVEs total

CVE-2026-263227.6 HIGHOpenClaw Gateway tool allowed unrestricted gatewayUrl override
CVE-2026-263167.5 HIGHOpenClaw has BlueBubbles webhook auth bypass via loopback proxy trust
CVE-2026-263197.5 HIGHOpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated Re
CVE-2026-254747.5 HIGHOpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`
CVE-2026-263217.5 HIGHOpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension
CVE-2026-263247.5 HIGHOpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reach
CVE-2026-263257.2 HIGHOpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvals
CVE-2026-263177.1 HIGHOpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation e
CVE-2026-269726.7 MEDIUMOpenClaw has a Path Traversal in Browser Download Functionality
CVE-2026-263286.5 MEDIUMOpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
CVE-2026-270095.8 MEDIUMOpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inl
CVE-2026-26327OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning
CVE-2026-26326OpenClaw skills.status could leak secrets to operator.read clients
CVE-2026-26329OpenClaw has a path traversal in browser upload allows local file read
CVE-2026-26323OpenClaw has a command injection in maintainer clawtributors updater
CVE-2026-27001OpenClaw: Unsanitized CWD path injection into LLM prompts
CVE-2026-27002OpenClaw: Docker container escape via unvalidated bind mount config injection
CVE-2026-27003OpenClaw: Telegram bot token exposure via logs
CVE-2026-27007OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container rec
CVE-2026-27008OpenClaw hardened the skill download target directory validation

Showing 20 of 22 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-27004へのコメント

まだコメントはありません


コメントを残す