


Perceptive Security
SOC/SIEM Consultancy

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script …
Published:
30 juli 2026 om 00:00:00
Alert date:
31 juli 2026 om 00:03:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities, Identity & Access
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting (XSS) vulnerability tracked as CVE-2026-66418. Unauthenticated remote attackers can inject arbitrary HTML and JavaScript by submitting a crafted username in a failed login POST request. The malicious input is recorded verbatim in the audit log without sanitization. When an administrator views the notification panel, the unescaped log entry is rendered via innerHTML. A permissive Content-Security-Policy allows inline event handlers, enabling the payload to execute in the administrator's browser session. This can allow attackers to interact with authenticated endpoints, edit agent instruction files, and make configuration changes, effectively leading to administrator account takeover.
Technical details
Mitigation steps:
Affected products:
OpenClaw Dashboard v3.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-66418
https://github.com/theopaid/Unauthenticated-Stored-Cross-Site-Scripting-Leading-To-Administrator-Account-Takeover
https://github.com/tugcantopaloglu/openclaw-dashboard
https://www.vulncheck.com/advisories/openclaw-dashboard-stored-xss-via-failed-login-username-field
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
