CVE-2026-101879 Details
Description
OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.
A missing authorization vulnerability has been identified in OpenClaw Windows Node versions prior to 2026.7.1-3. This vulnerability allows connected gateways or agents to perform screen snapshots, camera captures, and location tracking without user consent. The issue arises in the NodeService capture handlers, where the 'screen.snapshot', 'camera.snap', and 'location.get' commands can be invoked over the node WebSocket. As a result, screenshots can be taken, webcam photos can be captured, and device geolocation can be obtained silently, without any user interaction.
Users can update to OpenClaw Windows Node version 2026.7.1-3 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenClaw Windows Node | >= 0, < 2026.7.1-3 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion