No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openclaw
Openclaw diagnostics-prometheus |
|
| Vendors & Products |
Openclaw
Openclaw diagnostics-prometheus |
Sat, 26 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read scope can retrieve the diagnostics document even though ordinary read methods reject the same identity, disclosing operational metrics to an authenticated profile intentionally limited below read access. Shared-secret Gateway callers already hold the documented full operator scope and are not affected. The issue is fixed in 2026.9.3; as a workaround, disable the Prometheus endpoint or ensure every identity that can reach it is intended to hold operator.read. | |
| Title | OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T17:18:09.021Z
Reserved: 2026-09-26T01:00:40.147Z
Link: CVE-2026-100525
Updated: 2026-09-29T17:18:01.305Z
Status : Deferred
Published: 2026-09-26T03:16:57.563
Modified: 2026-09-29T18:17:05.507
Link: CVE-2026-100525
No data.
OpenCVE Enrichment
Updated: 2026-09-26T22:18:32Z