What is CVE-2026-66418?
OpenClaw Dashboard v3.0.0 has a stored XSS vulnerability that allows unauthenticated remote attackers to inject malicious script payloads via crafted usernames in failed login requests, which are recorded in the audit log and later executed when viewed by an administrator. It is recommended to sanitize all user inputs and update to a patched version.
Azərbaycanca: OpenClaw Dashboard v3.0.0-da saxlanılan XSS zəifliyi aşkar edilib ki, bu da autentifikasiya olunmamış uzaqdan hücum edənlərə uğursuz giriş cəhdlərini audit jurnalına qeyd etməklə zərərli skript yükləməyə imkan verir. Administrator jurnalı nəzərdən keçirərkən həmin yüklər işə düşür. İstifadəçi tərəfindən idarə olunan bütün girişlərin kodlaşdırılması və proqram təminatının yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can an attacker inject a malicious script into the audit log via CVE-2026-66418?
An unauthenticated attacker injects a specially crafted malicious script into the username field during a failed login request. This payload is recorded in the audit log and later executed when an administrator reviews the log.
Which version of OpenClaw Dashboard is affected by CVE-2026-66418?
OpenClaw Dashboard v3.0.0 is affected by this stored XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.