PatchSiren cyber security CVE debrief
CVE-2026-100530 OpenClaw CVE debrief
OpenClaw versions before 2026.8.1 have a vulnerability where approved commands can be executed in different directories due to a failure in binding working directory context to reusable exec approvals. This allows attackers with an allow-always approval to reuse it to run the same command against unreviewed files or repositories with materially different effects.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders and administrators using OpenClaw versions before 2026.8.1 should assess exposure and prioritize verification and remediation. Relevant roles include OpenClaw administrators, defenders, and security teams responsible for vulnerability management and ensuring the security of OpenClaw deployments.
Why it matters
Defenders should care about CVE-2026-100530 as it allows attackers to execute approved commands in different directories, potentially leading to unauthorized actions. Relevant roles include OpenClaw administrators and defenders. Supported consequences include verifying OpenClaw versions, reviewing exec approvals, and monitoring command executions. Evidence limits include limited information on exploitation or affected versions.
- Verify OpenClaw versions and ensure upgrades to 2026.8.1 or later to prevent directory binding issues
- Review exec approvals and their usage to prevent unauthorized command executions
- Monitor for suspicious command executions to detect potential attacks
Technical summary
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. This vulnerability allows attackers with an allow-always approval to reuse it to run the same command against unreviewed files or repositories with materially different effects. The vulnerability affects OpenClaw deployments, and defenders should prioritize verifying OpenClaw versions and ensuring upgrades to 2026.8.1 or later, reviewing exec approvals and their usage, and monitoring for suspicious command executions.
Defensive priority
Defenders should prioritize verifying OpenClaw versions and ensuring upgrades to 2026.8.1 or later, reviewing exec approvals and their usage, and monitoring for suspicious command executions.
Recommended defensive actions
- Verify OpenClaw versions and ensure upgrades to 2026.8.1 or later
- Review exec approvals and their usage
- Monitor for suspicious command executions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected versions is limited. OpenClaw versions before 2026.8.1 are affected, and defenders should verify OpenClaw deployments, review exec approvals, and monitor command executions. Evidence limits include limited information on exploitation or affected versions, and defenders should exercise caution when verifying affected scope.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100530 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100530
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100530 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100530
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-3mq7-q27j-mq7q
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-exec-approval-directory-binding
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.