CVE-2026-95815

6.3

OpenClaw · OpenClaw iOS

OpenClaw iOS logs full deep-link URLs containing persistent bearer keys to public diagnostic logs, allowing attackers to recover keys and replay requests without user interaction.

Executive summary

A vulnerability in OpenClaw iOS versions prior to 2026.8.11 exposes persistent bearer keys in diagnostic logs, creating a high risk of unauthorized agent access and command execution.

Vulnerability

The application incorrectly handles sensitive data by writing complete agent deep-link URLs, which include persistent bearer keys, to unified diagnostic logs. An attacker with access to these logs can extract these keys and replay them to perform unauthorized actions as the user without requiring further authentication or local confirmation prompts.

Business impact

Successful exploitation allows an attacker to bypass critical security controls and execute commands as the victim user. Because the leaked credentials are persistent bearer keys, this compromise can lead to long-term unauthorized access to the user's agent environment, potential data exfiltration, or the triggering of unauthorized operations, resulting in significant operational and privacy risks.

Remediation

Immediate Action: Update OpenClaw iOS to version 2026.8.11 or later immediately to prevent the logging of sensitive bearer keys.

Proactive Monitoring: Review system diagnostic logs for any entries containing deep-link URLs or unexpected authentication tokens, and rotate any credentials that may have been present in existing diagnostic archives.

Compensating Controls: Ensure that device diagnostic data is encrypted and restricted to authorized personnel only, and implement strict access controls on any log aggregation or analysis platforms.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The exposure of persistent bearer keys constitutes a severe security failure that bypasses intended user confirmation workflows. Organizations utilizing OpenClaw iOS must prioritize the transition to version 2026.8.11 across all managed devices to ensure that credential material is no longer written to insecure diagnostic logs.

More OpenClaw CVEs all →

History

  1. Analyst report written

Sources

Originally found and disclosed by Jason O'Neal (jason-allen-oneal), per the CVE Program record.