CVE-2026-100568
Received Received - Intake

OpenClaw Pre-2026.8.1 Command Job Access Bypass

Vulnerability report for CVE-2026-100568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw versions before 2026.8.1 have an access control flaw in their cron job system. Lower-privilege agent callers can read and execute operator command jobs that were intended only for administrators. This allows them to inspect environment variables and run disabled or unscheduled jobs, potentially accessing secrets or executing commands.

Detection Guidance

Check OpenClaw versions prior to 2026.8.1 by running version inspection commands like 'openclaw --version' or examining installed package metadata. Review cron job configurations for ownerless command jobs accessible by lower-trust agents. Inspect environment variables stored in command jobs for sensitive data exposure.

Impact Analysis

Attackers could exploit this to access sensitive environment variables, run unauthorized commands, or execute jobs outside their scheduled time. This may lead to data breaches, privilege escalation, or system compromise depending on the commands and secrets stored in the affected jobs.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data (e.g., personal or health information) through unauthorized access to environment variables or command execution. Organizations may face penalties for failing to protect regulated data under standards like GDPR or HIPAA.

Mitigation Strategies

Upgrade OpenClaw to version 2026.8.1 or later immediately. Remove the cron tool from lower-trust agents to prevent unauthorized access. Avoid storing sensitive environment values in ownerless command jobs. Review and restrict access to existing command jobs to ensure only authorized operators can execute them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart