Information disclosure in OpenClaw - CVE-2026-26326
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the skills.status gateway method when returning requirement reports for skill requires.config paths. A remote user can call the method and obtain raw resolved configuration values to disclose sensitive information.
If a skill requires a broad configuration subtree, the returned configChecks data may include secrets such as Discord bot tokens.