CVE-2026-91836
CVE-2026-91836 is a low-severity vulnerability with a CVSS 3.x base score of 2.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1023.
Key facts
- Severity: Low (CVSS 3.x base score 2.8)
- CVSS v2: 1.7
- CVSS v4: 0.9
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1023
- Published:
- Last modified:
Description
A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version 0.1.7 mitigates this issue. Patch name: 9f6a6fbb9f1137345566d0ab44c73893dfe112fa. The affected component should be upgraded.
Frequently asked questions
- What is CVE-2026-91836?
- A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version 0.1.7 mitigates this issue. Patch name: 9f6a6fbb9f1137345566d0ab44c73893dfe112fa. The affected component should be upgraded.
- How severe is CVE-2026-91836?
- CVE-2026-91836 has a CVSS 3.x base score of 2.8, rated low severity. It is exploitable over local access with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-91836 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-91836?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-91836 published?
- CVE-2026-91836 was published on 2026-09-15 and last updated on 2026-09-20.
References
- https://github.com/openclaw/clawscan/
- https://github.com/openclaw/clawscan/commit/9f6a6fbb9f1137345566d0ab44c73893dfe112fa
- https://github.com/openclaw/clawscan/issues/40
- https://github.com/openclaw/clawscan/pull/41
- https://github.com/openclaw/clawscan/releases/tag/v0.1.7
- https://vuldb.com/cve/CVE-2026-91836
- https://vuldb.com/submit/933533
- https://vuldb.com/vuln/404072
- https://vuldb.com/vuln/404072/cti
Other CWE-1023 vulnerabilities
- CVE-2026-4599 — Critical (CVSS 9.1): Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing…
- CVE-2026-24255 — High (CVSS 7.5): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a…
- CVE-2025-62000 — High (CVSS 7.1): BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection…
- CVE-2026-91768 — Medium (CVSS 6.5): The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so…
- CVE-2026-53839 — Medium (CVSS 6.5): OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching…
- CVE-2025-55333 — Medium (CVSS 6.1): Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security…