---
cve: "CVE-2026-66418"
severity: "CRITICAL"
cvss: 9.3
epss: "34%"
vendor: "tugcantopaloglu"
kev: false
exploited: false
published: "2026-07-30 21:18:12"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-04T22:48:47+02:00"
---

# CVE-2026-66418

> 9.3 CRITICAL · 🧪 PoC

## Beschreibung

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent instruction file editing and configuration changes.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Referenzen

- <https://github.com/tugcantopaloglu/openclaw-dashboard>
- <https://github.com/theopaid/Unauthenticated-Stored-Cross-Site-Scripting-Leading-To-Administrator-Account-Takeover>
- <https://www.vulncheck.com/advisories/openclaw-dashboard-stored-xss-via-failed-login-username-field>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-66418) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
