Skip to content
High-Risk Vulnerabilities in OpenClaw Windows Node Disclosed

High-Risk Vulnerabilities in OpenClaw Windows Node Disclosed

First seen 1 Oct 2026, 01:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 01:59 UTC

Two vulnerabilities, CVE-2026-101880 and CVE-2026-101884, were disclosed for OpenClaw Windows Node versions prior to 2026.7.1. CVE-2026-101880 allows arbitrary command execution via an authorization bypass, while CVE-2026-101884 enables remote code execution through environment variable manipulation. Both vulnerabilities are rated high severity, with CVSS scores of 8.7 and 7.7 respectively. Attackers with low privileges can exploit these flaws to gain control over affected Windows hosts, potentially leading to data theft or service disruption. No active exploitation has been confirmed, but proof-of-concept indicators exist. Organizations using OpenClaw should prioritize patching and restricting access to vulnerable nodes. The vulnerabilities were published on September 30, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-101880 published
CVE-2026-101880 disclosed, allowing arbitrary command execution on vulnerable Windows nodes.
Redpacketsecurity
2026-09-30
CVE-2026-101884 published
CVE-2026-101884 disclosed, enabling remote code execution via environment variable manipulation.
Redpacketsecurity

More articles in this cluster (5)

Following this threat?

Track CVE-2026-101880 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
OpenClaw Windows Node versions before 2026.7.1 are affected by these vulnerabilities.
Is there any active exploitation?
No active exploitation has been confirmed, but proof-of-concept indicators exist.
What should organizations do?
Organizations should prioritize upgrading to the fixed release and restrict access to vulnerable nodes.