PT-2026-21337 · Openclaw · Openclaw
Aether-Ai-Agent
·
Published
2026-02-18
·
Updated
2026-04-10
·
CVE-2026-27486
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.14
Description
OpenClaw is a personal AI assistant. The CLI process cleanup mechanism used system-wide process enumeration and pattern matching to terminate processes without verifying ownership by the current OpenClaw process. On shared hosts, unrelated processes could be terminated if they matched the specified pattern. The CLI runner cleanup helpers could terminate processes matched by command-line patterns without validating process ownership.
Recommendations
Update to version 2026.2.14 or later.
Exploit
Fix
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw