CVE-2026-32016 Details
Description
OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. Attackers can execute same-name local binaries ./echo without approval when security=allowlist and ask=on-miss are configured, bypassing intended path-based policy restrictions.
A path validation bypass vulnerability has been identified in OpenClaw versions prior to 2026.2.22 on macOS. This vulnerability exists in the exec-approval allowlist mode, where basename-only allowlist entries can be exploited by local attackers to execute unauthorized binaries. When the 'security' setting is configured to 'allowlist' and 'ask' is set to 'on-miss', attackers can run local binaries with the same name, such as './echo', without proper approval. This bypasses the intended path-based policy restrictions, allowing unauthorized execution of commands.
Users can update to OpenClaw version 2026.2.22 or later, which enforces path-only allowlist matching, removes basename fallback, and migrates legacy basename entries to their last-resolved paths when available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.2.22 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | CVE Modified | [email protected] |
| Mar 24, 2026 | Initial Analysis | [email protected] |
| Mar 19, 2026 | New CVE Received | [email protected] |