Vulnerability  ·  2026-09-27

OpenClaw AI agent gateway: mass disclosure of 20+ CVEs — sandbox escapes, exec-approval and owner-only authorization bypasses (CVE-2026-100544 and cluster)

VulnerabilityHigh impactGlobalCVE-2026-100544
Versions before 2026.7.1/2026.8.1 shipped with numerous authorization and sandboxing deficiencies across the gateway, voice-call, MCP bridge, cron, and browser-tool components. Ten+ GitHub security advisories were published 2026-09-25/26 (GHSA-rrxp-5mx8-mvhh, GHSA-ghpx-6xwq-2w4w, GHSA-wwx7-573h-pqwc, GHSA-hpg5-cq3m-phqp, GHSA-9x88-f7rh-4c83, etc.). An earlier (April 2026) 'Claw Chain' set chained four CVEs into a CVSS 9.6 sandbox escape, and ClawHub skill-registry supply-chain campaigns delivered malware to 800+ skills.
This is the largest single-vendor AI-agent vulnerability batch in the window. In a typical deployment the agent has elevated access to files, shell, browser, and connected services; these are agent-targeted authorization bypasses that let a remote voice caller, a non-owner channel sender, or prompted sandboxed agent reach owner-level tool authority — reading files/secrets, executing commands, and controlling connected services. Upgrade to >=2026.8.11, restrict agent permissions, audit installed ClawHub skills, and treat external-channel callers as untrusted.
Several distinct vectors: (1) classic inbound voice calls launch the configured agent without propagating caller identity, so owner-only tool filtering fails open (CVE-2026-100544, CVSS 8.8); (2) operator/exec approval policies can be bypassed (CVE-2026-100561, CVE-2026-100552, CVE-2026-100580, CVE-2026-100599); (3) non-owner external-channel senders can persist stdio MCP commands that run with OpenClaw process privileges (/mcp set — CVE-2026-100596) or install malicious Codex plugins (CVE-2026-100587); (4) model-visible callers can read/execute ownerless cron jobs and stored secrets (CVE-2026-100568); (5) browser-tool sandbox bypass lets sandboxed sessions reach paired-node host browser actions (CVE-2026-100589); (6) DNS-rebinding/TOCTOU gaps in CDP hostname handling (CVE-2026-100567, CVE-2026-100584).
Upgrade OpenClaw/openclaw to 2026.8.11 or later (fixes span 2026.7.1–2026.8.11); disable inbound calling until patched; rotate credentials if any exposure suspected. Advisories: https://github.com/openclaw/openclaw/security/advisories
GitHub OpenClaw security advisory (voice-call, CVE-2026-100544)threataft.com OpenClaw mass disclosure analysisNVD - CVE-2026-100544
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →