← Vulnerability feed

Vulnerability record · CVE-2026-32982 · published 31 March 2026

CVE-2026-32982: Openclaw sensitive information in log file vulnerability

Openclaw · Openclaw

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.

8.7 CVSS 4.0 High EPSS 0.51% · top 59.2% CWE-532 · Sensitive information in log file
8.7CVSS 4.0 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
25 Jul 2026Last modified by NVD

Description

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-32982 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-30741Openclaw code injection vulnerabilityA remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt…EPSS 1.2%9.4CVE-2026-33579Openclaw incorrect authorization vulnerabilityOpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…EPSS 0.51%9.4CVE-2026-32978Openclaw incorrect authorization vulnerabilityOpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri…EPSS 0.32%9.4CVE-2026-32922Openclaw vulnerabilityOpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min…EPSS 0.69%9.4CVE-2026-22172Openclaw missing authorization vulnerabilityOpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…EPSS 0.56%9.4CVE-2026-28466Openclaw incorrect authorization vulnerabilityOpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…EPSS 0.67%9.3CVE-2026-43534Openclaw insufficient verification of data authenticity vulnerabilityOpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Atta…EPSS 0.30%9.3CVE-2026-32987Openclaw authentication bypass by capture-replay vulnerabilityOpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers …EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2026-32982), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.