Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority. | |
| Title | OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-312 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T02:19:06.796Z
Reserved: 2026-09-26T01:03:42.740Z
Link: CVE-2026-100581
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-312
Cleartext Storage of Sensitive Information