Incomplete Validation Vulnerability in OpenClaw Windows Node
CVE-2026-101882
8.7HIGH
What is CVE-2026-101882?
The OpenClaw Windows Node prior to version 2026.7.1 is susceptible to a vulnerability that permits remote calls to execute arbitrary commands on the Windows host. This is accomplished through the system.execApprovals.set method, which fails to adequately validate wildcard-executable rules, allowing potentially harmful binaries such as mshta, rundll32, and certutil to be exploited. As a result, this can lead to unauthorized command execution without the need for operator checks or user confirmations.
Affected Version(s)
OpenClaw Windows Node 0 < 2026.7.1
