PT-2026-31977 · Openclaw · Openclaw

Edward-X

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35666

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.22
Description A flaw exists in OpenClaw that allows attackers to bypass restrictions on executable bindings. This is achieved by misusing time wrappers within the system.run approvals functionality. Specifically, the vulnerability lies in the failure to properly unwrap /usr/bin/time wrappers, enabling an allowlist bypass. Attackers can reuse approval state for inner commands by utilizing an unregistered time wrapper.
Recommendations Update to version 2026.3.22 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35666
GHSA-QM9X-V7CX-7RQ4

Affected Products

Openclaw