CVE-2026-100551

8.3

OpenClaw · OpenClaw for iOS

OpenClaw for iOS fails to enforce TLS certificate pinning in specific WebViews, allowing attackers to intercept credentials and gain unauthorized operator access to Gateway systems.

Executive summary

A critical vulnerability in OpenClaw for iOS allows attackers to perform a man-in-the-middle attack to steal sensitive operator credentials and gain unauthorized control over Gateway infrastructure.

Vulnerability

This flaw is an improper certificate validation issue (CWE-295) where the application fails to enforce saved TLS pins within the Control UI WebViews. An attacker capable of redirecting traffic can present a spoofed certificate to capture authentication tokens or passwords when a user accesses the Terminal or Dashboard.

Business impact

The exploitation of this vulnerability leads to a total compromise of operator sessions, granting attackers the ability to read sensitive gateway state and execute host-capable tools. Given the CVSS score of 8.3, this represents a significant risk to operational integrity and data confidentiality. Unauthorized access to these systems can lead to severe operational disruption and potential exfiltration of sensitive infrastructure data.

Remediation

Immediate Action: Update the OpenClaw for iOS application to version 2026.8.11 or later immediately to restore mandatory TLS pin enforcement.

Proactive Monitoring: Review network traffic logs for unexpected redirection attempts or suspicious certificate responses originating from connections to Gateway hosts.

Compensating Controls: Utilize a secure, managed VPN or private network tunnel to access sensitive Gateways, which reduces the likelihood of an attacker successfully redirecting host connections.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by this vulnerability is high due to the potential for total credential theft and unauthorized administrative access. Administrators must ensure all instances of the OpenClaw iOS application are updated to version 2026.8.11 as a priority. Failure to patch will leave users susceptible to credential harvesting attacks that bypass standard trust mechanisms.

More OpenClaw CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by 0xca1x, with migraine-sudo (analyst), per the CVE Program record.