{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/codex--2026.7.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openclaw:codex:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-100586"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Codex (\u003c 2026.7.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenClaw"],"content_html":"\u003cp\u003eOpenClaw Codex versions prior to 2026.7.1 are susceptible to an authorization bypass vulnerability (CVE-2026-100586) involving the creation of native conversation bindings. The vulnerability stems from a failure to properly validate authorization levels when a user attempts to bind a conversation to the native Codex runtime. An attacker who is a channel participant, even without owner-level privileges, can leverage this flaw to create unauthorized bindings.\u003c/p\u003e\n\u003cp\u003eOnce a malicious binding is established, the attacker can execute \u0026quot;host-capable\u0026quot; turns. Because these turns are processed by the native Codex runtime, they inherit the privileges of the application process itself. This allows for unauthorized interaction with the host file system, execution of local system tools, and potential manipulation of running processes. Given the severity of the access provided, this vulnerability represents a significant risk to host environment integrity and data confidentiality. Defenders should prioritize patching all instances of OpenClaw Codex to version 2026.7.1 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unprivileged channel participants to gain elevated access within the host environment. This can lead to unauthorized exfiltration of sensitive files, execution of malicious system commands, and potential lateral movement or persistence by manipulating system processes. The scope of impact is limited to the system where the affected Codex instance is running.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all internet-facing and internal installations of OpenClaw Codex to version 2026.7.1 or later to remediate CVE-2026-100586.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal creation of native conversation bindings or execution of unexpected host-level commands originating from non-owner user accounts.\u003c/li\u003e\n\u003cli\u003eEnforce strict network segmentation for hosts running the Codex runtime to limit potential post-exploitation activity if the service is compromised.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T06:57:37Z","date_published":"2026-09-26T06:57:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-codex-auth-bypass/","summary":"OpenClaw Codex versions before 2026.7.1 contain an authorization bypass vulnerability allowing non-owner users to create native conversation bindings and execute arbitrary host-level commands.","title":"Authorization Bypass Vulnerability in OpenClaw Codex","url":"https://feed.craftedsignal.io/briefs/2026-09-openclaw-codex-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Codex (\u003c 2026.7.1)","version":"https://jsonfeed.org/version/1.1"}