PT-2026-26391 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-32009

CVSS v3.1

5.7

Medium

AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that trusts static default directories including writable package-manager paths like /opt/homebrew/bin and /usr/local/bin. An attacker with write access to these trusted directories can place a malicious binary with the same name as an allowed executable to achieve arbitrary command execution within the OpenClaw runtime context.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2026-32009

Affected Products

Openclaw