CVE-2026-100528
5.4 MEDIUMpublic exploit availablePublished 2026-09-26 · Updated 2026-09-30
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L
Weaknesses
CWE-200
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-100241
- UNSCOREDCVE-2026-100244
- MEDIUMCVE-2026-100286
- UNSCOREDCVE-2026-100377
- UNSCOREDCVE-2026-100379PoC
- MEDIUMCVE-2026-100418PoC
- HIGHCVE-2026-100543PoC
- MEDIUMCVE-2026-100548PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.