CPE
OpenClaw Codex versions before 2026.7.1 contain an authorization bypass vulnerability allowing non-owner users to create native conversation bindings and execute arbitrary host-level commands.