Skip to content
CVE Alert: CVE-2026-101880 – OpenClaw

CVE Alert: CVE-2026-101880 – OpenClaw

Redpacketsecurity •admin • October 1, 2026

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.

**Risk verdict:** High priority for any exposed, vulnerable Windows node; a proof-of-concept indicator exists, but the supplied data does not establish active exploitation or KEV inclusion.

**Why this matters:** A low-privilege gateway or agent connection could turn restricted command execution into control of the Windows host, enabling data theft, tampering, service disruption or a foothold for follow-on activity. SSVC indicates total technical impact but says exploitation is not automatable; EPSS is not provided, so likelihood cannot be quantified.

**Most likely attack path:** A network-reachable node accepts a request from an actor with low privileges, who uses shell syntax that the approval parser mishandles to run a command that should be denied. No user interaction or special attack conditions are required; scope is unchanged, so impacts are primarily on the affected host, though stolen credentials or access to nearby systems could enable lateral movement.

**Who is most exposed:** Prioritise Windows nodes that accept connections from untrusted or broadly reachable gateways, agents, or users. Centrally managed deployments and hosts with valuable credentials or operational roles merit particular attention.

Hunt process command lines containing pipes or command substitutions, especially where approval records show only an allowed prefix.

Correlate node requests, approval decisions and child-process creation for mismatches.

Review unexpected shells, script interpreters, new services, scheduled tasks and outbound connections.

Mitigation and prioritisation

Upgrade promptly to the vendor’s fixed release; verify every Windows node is remediated.

Restrict gateway and agent access to trusted identities and network segments.

Until patched, disable or tightly constrain command execution where operationally feasible.

Preserve relevant logs and validate change impact before broad rollout.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities