HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-100596 — OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users exe...
·Source: NIST NVD
Updated:
Executive Summary
OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.
Analysis
OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability. CVSS Score: 8.8. Published: 2026-09-26T03:17:08.187.