CVE-2026-100587
Received Received - Intake

OpenClaw before 2026.7.1 Authorization Bypass via Codex Plugin Installation

Vulnerability report for CVE-2026-100587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileges, affecting host confidentiality, integrity, and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenClaw versions before 2026.7.1 have a flaw where owner authorization is not properly validated for the Codex computer-use installation command. This allows non-owner channel senders to install arbitrary plugins and execute MCP processes with the privileges of the OpenClaw user.

Detection Guidance

To detect this vulnerability, check the installed version of OpenClaw. If it is before 2026.7.1, the system is vulnerable. Run: npm list openclaw or check the package version in your project files. Additionally, review channel configurations to ensure Codex computer-use installation is disabled.

Impact Analysis

This vulnerability can lead to unauthorized installation of malicious plugins, execution of arbitrary processes, and compromise of host system confidentiality, integrity, and availability due to the elevated privileges gained by attackers.

Compliance Impact

This vulnerability could lead to unauthorized access and execution of malicious code on systems running OpenClaw, potentially resulting in data breaches. For GDPR, this may violate principles of data protection and user rights. For HIPAA, it could compromise protected health information integrity and confidentiality.

Mitigation Strategies

Immediately upgrade OpenClaw to version 2026.7.1 or later to address the authorization validation flaw in the Codex computer-use installation command.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart