CVE-2026-100569
5.5 MEDIUMpublic exploit availablePublished 2026-09-26 · Updated 2026-09-30
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filter did not block variables ending in `_ENDPOINT`, so an untrusted workspace `.env` file could set AZURE_SPEECH_ENDPOINT. Azure Speech preferred that value over the configured region, so when a synthesis or voice-list request was made, the attacker-selected endpoint received the operator's Azure Speech key in the request header, allowing the key to be reused against the operator's Azure Speech resource. Exploitation requires an operator to start OpenClaw in attacker-controlled workspace content with Azure Speech configured with a key and region and no trusted endpoint override set. The issue is fixed in 2026.8.1.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses
CWE-522
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100298
- LOWCVE-2026-101089PoC
- HIGHCVE-2026-17643
- MEDIUMCVE-2026-18124
- CRITICALCVE-2026-20234
- HIGHCVE-2026-48976PoC
- LOWCVE-2026-49449PoC
- UNSCOREDCVE-2026-55870PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.