CVE-2026-100560: Openclaw
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.
Affected products
- Openclaw Openclaw: before 2026.8.1 (fixed in 2026.8.1)
Published 2026-09-26. Last modified 2026-09-30.