CVE-2026-100560
Received Received - Intake

Authorization Bypass in OpenClaw via Persistent Path-Only Grants

Vulnerability report for CVE-2026-100560, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without triggering new approval prompts, potentially accessing files or internal services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw versions before 2026.8.1 have an authorization bypass flaw where 'Allow Always' approvals for exact commands persist as path-only grants on macOS and Linux. Attackers can reuse the same executable with different arguments to execute commands without new approval prompts, potentially accessing files or internal services.

Detection Guidance

Check OpenClaw logs for repeated executions of the same executable with varying arguments. Look for entries where an executable was previously granted 'Allow Always' but is now being used with different parameters without new approval prompts.

Impact Analysis

This vulnerability allows attackers to execute unauthorized commands with modified arguments, potentially accessing sensitive files, overwriting user files, or interacting with internal services without further approval. Exploitation requires a prior persistent approval for the same executable.

Compliance Impact

The vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Unauthorized file access or service interactions may result in non-compliance with data protection and security standards.

Mitigation Strategies

Upgrade OpenClaw to version 2026.8.1 or later. Remove any existing 'Allow Always' approvals for executables before upgrading to prevent persistent path-only grants from being carried forward.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100560. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart