HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-101880 — OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulner...

·Source: NIST NVD

Updated:

Executive Summary

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving

Analysis

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts. CVSS Score: 8.8. Published: 2026-09-30T20:17:18.857.

Indicators of Compromise (1)

CVE (1)
CVE-2026-101880
Source Attribution

Originally published by NIST NVD on Sep 30, 2026. Verified by: NIST.

Related Threats