Authorization Bypass in OpenClaw Windows Node by OpenClaw
CVE-2026-101879

7.1HIGH

Key Information:

Vendor

Openclaw

Vendor
CVE Published:
30 September 2026

What is CVE-2026-101879?

OpenClaw Windows Node prior to version 2026.7.1-3 contains a vulnerability that allows connected gateways or agents to silently capture sensitive user information. This missing authorization flaw permits attackers to invoke functions over the Node WebSocket, enabling them to take screenshots, access webcam feeds, and acquire geolocation data without user consent. Immediate updates are recommended to mitigate these serious security implications.

Affected Version(s)

OpenClaw Windows Node 0 < 2026.7.1-3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cameron Beeley (anagnorisis2peripeteia)
.