PT-2026-26227 · Openclaw · Openclaw

·

CVE-2026-29607

·

Publicado

2026-02-23

·

Atualizado

2026-04-01

CVSS v2.0

8.3

Alta

VetorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22 OpenClaw versions 2026.2.21-2 and earlier
Description The software contains an authorization bypass issue in the allow-always wrapper persistence feature. This allows attackers to bypass approval checks by persisting wrapper-level allowlist entries instead of validating the intended execution. This can lead to remote code execution on gateway and node-host execution flows. Specifically, approving wrapped system.run commands with allow-always in security=allowlist mode could persist wrapper-level allowlist entries, enabling subsequent approval-bypass execution of different inner payloads. The issue stems from basing allow-always persistence on wrapper-level resolution rather than stable inner executable intent. Affected paths include gateway and node-host execution approval persistence flows.
Recommendations Upgrade to version 2026.2.22. As an alternative, run the software with a stricter execution policy (ask=always or security=deny) until upgraded.

Exploit

Correção

Incorrect Authorization

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05016
CVE-2026-29607
GHSA-6J27-PC5C-M8W8
GHSA-PFV5-RPCW-X34X

Produtos afetados

Openclaw