CVE-2026-4040 Details
Description
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs to be performed locally. Upgrading to version 2026.2.19-beta.1 is capable of addressing this issue. The identifier of the patch is bafdbb6f112409a65decd3d4e7350fbd637c7754. Upgrading the affected component is advised.
A vulnerability allowing information disclosure through a file-existence oracle has been identified in OpenClaw versions prior to 2026.2.17. This issue arises in the 'tools.exec.safeBins' function within the File Existence Handler component. The vulnerability requires local exploitation and could be used to infer the presence of specific files on the host system, such as configuration or secret files, thereby aiding in filesystem enumeration and follow-on attack planning.
Users are advised to upgrade to OpenClaw version 2026.2.19-beta.1, which addresses this vulnerability by removing the file-existence oracle behavior and implementing a more secure validation process for safeBins.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/openclaw/ | [email protected] | Product |
| https://github.com/openclaw/openclaw/commit/bafdbb6f112409a65decd3d4e7350fbd637c7754 | [email protected] | Patch |
| https://github.com/openclaw/openclaw/releases/tag/v2026.2.19-beta.1 | [email protected] | Release Notes |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-6c9j-x93c-rw6j | [email protected] | Vendor Advisory |
| https://vuldb.com/?ctiid.350652 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.350652 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.769581 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-203 | Observable Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | >= 2026.2.0, < 2026.2.19 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | Initial Analysis | [email protected] |
| Mar 12, 2026 | New CVE Received | [email protected] |