CVE-2026-100586: Openclaw

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.

Affected products

  • Openclaw Openclaw: before 2026.7.1 (fixed in 2026.7.1)

Published 2026-09-26. Last modified 2026-09-28.