Skip to content
Threat Feed
high advisory

Authorization Bypass in OpenClaw Windows Node via Command Injection

An incorrect authorization vulnerability in OpenClaw Windows Node version < 2026.7.1 allows unauthenticated agents to achieve arbitrary command execution by bypassing command approval policies.

CVE search metadata

CVE search record: CVE-2026-101880. Severity: high. CVSS: 8.8. KEV: no. Product: Windows Node (< 2026.7.1). Brief: Authorization Bypass in OpenClaw Windows Node via Command Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-09-openclaw-auth-bypass/

OpenClaw Windows Node version 2026.7.1 and earlier contains an incorrect authorization vulnerability in the system.run exec-approval policy. The vulnerability resides within the ExecShellWrapperParser component, which fails to correctly tokenize or sanitize input commands. Specifically, the parser does not properly handle pipe operators or command substitution syntax, allowing a malicious or compromised gateway/agent to append denied commands to otherwise authorized prefixes. By exploiting this parsing logic, an attacker can bypass defined approval rules, leading to unauthorized arbitrary command execution on the host operating system. This issue poses a high risk to organizations relying on OpenClaw for automated system management and task execution.

Impact

Successful exploitation allows for arbitrary code execution on systems running the OpenClaw Windows Node. This can lead to full system compromise, lateral movement within the environment, and exfiltration of sensitive data, depending on the privileges of the service account running the OpenClaw node agent.

Recommendation

Update all instances of OpenClaw Windows Node to version 2026.7.1 or later immediately. Review audit logs for system.run command executions that contain pipe characters or command substitution syntax to identify potential prior exploitation attempts.


Immediate actions

Upgrade OpenClaw Windows Node to version 2026.7.1 or later

IT Operations 48h

Threat Hunt

Audit logs for system.run containing pipe operators (|) or command substitution (e.g., $())

T1059.003 medium medium confidence hunt now

Data: Application logs containing command parameters

Mitigations

Upgrade OpenClaw Windows Node to 2026.7.1

immediate IT Operations

CVE-2026-101880