PT-2026-21337 · Openclaw · Openclaw

Aether-Ai-Agent

·

Published

2026-02-18

·

Updated

2026-04-10

·

CVE-2026-27486

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description OpenClaw is a personal AI assistant. The CLI process cleanup mechanism used system-wide process enumeration and pattern matching to terminate processes without verifying ownership by the current OpenClaw process. On shared hosts, unrelated processes could be terminated if they matched the specified pattern. The CLI runner cleanup helpers could terminate processes matched by command-line patterns without validating process ownership.
Recommendations Update to version 2026.2.14 or later.

Exploit

Fix

LPE

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-27486
GHSA-JFV4-H8MC-JCP8

Affected Products

Openclaw