Authorization Bypass Vulnerability in OpenClaw by OpenClaw Team
CVE-2026-100560

7.7HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100560?

OpenClaw versions prior to 2026.8.1 exhibit an authorization bypass vulnerability that allows attackers to reuse previously approved commands with altered arguments. On macOS and Linux, 'Allow Always' approvals for exact commands remain as path-only grants, enabling unauthorized command execution without additional approval prompts. This could potentially lead to unauthorized access to sensitive files or internal services, underscoring the need for timely updates to prevent exploitation.

Affected Version(s)

OpenClaw 0 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

anagnorisis2peripeteia
.