CVE-2026-101882 Details
Description
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.
A vulnerability exists in OpenClaw Windows Node versions prior to 2026.7.1, specifically within the exec approval system. The issue arises from inadequate validation in the 'system.execApprovals.set' command, which allows the introduction of wildcard-executable rules. This flaw can be exploited using commonly available system binaries such as mshta, rundll32, and certutil. Remote callers have the ability to append broad allow rules that enable the execution of arbitrary commands on the Windows host via 'system.run', all without the need for operator oversight or user interaction.
Users can update to OpenClaw Windows Node version 2026.7.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-184 | Incomplete List of Disallowed Inputs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenClaw Windows Node | <= 0.6.12 (semver) < 2026.7.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion