Vulnerability  ·  2026-09-27

OpenClaw 'dreaming' agent context poisoning — restricted sender persists instructions later executed by privileged background agent (CVE-2026-100535)

VulnerabilityHigh impactGlobalCVE-2026-100535
OpenClaw versions >=2026.4.5 and <2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory (GHSA-62qm-6fjj-6g23, CVSS 7.5). This is described as a new class of AI-specific privilege escalation: a low-privilege/restricted input becomes an authoritative instruction to an unattended privileged agent.
Represents a distinctive AI-specific privilege-escalation pattern — privilege/trust provenance is not carried through agent memory persistence, so content a restricted sender could never execute is later executed by a privileged background process. Defenders should enable requester-specific tool policies consistently across memory recall and dreaming paths, and upgrade to 2026.8.1+.
An attacker who can send a message to a restricted sender channel feeds crafted text into a session; because the persisted session memory strips the originating requester's tool restrictions, the background dreaming agent later acts on the embedded instructions with the agent's broader tool authority and the host's credentials.
Upgrade OpenClaw to 2026.8.1 or later; if unable, disable session-memory capture/dreaming. Advisory: https://github.com/openclaw/openclaw/security/advisories/GHSA-62qm-6fjj-6g23
NVD - CVE-2026-100535threataft.com OpenClaw analysis
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →