NVD HIGH: CVE-2026-100551 — OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gatew...
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by
CVE-2026-100551