CVE-2026-100600

CVE-2026-100600 published: ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance. A remote, unauthenticated caller can drain that shared al...

View full NVD advisory → ← Back to CVE watch