CVE Explorer
CVE-2026-26326
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only `{ path, satisfied }`) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to re
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openclaw","vendor":"openclaw","versions":[{"status":"affected","version":"< 2026.2.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/openclaw/openclaw/commit/d3428053d95eefbe10ecf04f92218ffcba55ae5a","tags":["x_refsource_MISC"],"url":"https://github.com/openclaw/openclaw/commit/d3428053d95eefbe10ecf04f92218ffcba55ae5a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/references/1
{"name":"https://github.com/openclaw/openclaw/commit/ebc68861a61067fc37f9298bded3eec9de0ba783","tags":["x_refsource_MISC"],"url":"https://github.com/openclaw/openclaw/commit/ebc68861a61067fc37f9298bded3eec9de0ba783"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/references/2
{"name":"https://github.com/openclaw/openclaw/releases/tag/v2026.2.14","tags":["x_refsource_MISC"],"url":"https://github.com/openclaw/openclaw/releases/tag/v2026.2.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/references/3
{"name":"https://github.com/openclaw/openclaw/security/advisories/GHSA-8mh7-phf8-xgfm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-8mh7-phf8-xgfm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f9fc94f89e5a2e357308bb40ff7fb021a14727328df93ab628ba3511fbf0e4e9 · sha256:2d31bd9d226b7d07… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.