PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100530 OpenClaw CVE debrief

OpenClaw versions before 2026.8.1 have a vulnerability where approved commands can be executed in different directories due to a failure in binding working directory context to reusable exec approvals. This allows attackers with an allow-always approval to reuse it to run the same command against unreviewed files or repositories with materially different effects.

Vendor
OpenClaw
Product
Unknown
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Defenders and administrators using OpenClaw versions before 2026.8.1 should assess exposure and prioritize verification and remediation. Relevant roles include OpenClaw administrators, defenders, and security teams responsible for vulnerability management and ensuring the security of OpenClaw deployments.

Why it matters

Defenders should care about CVE-2026-100530 as it allows attackers to execute approved commands in different directories, potentially leading to unauthorized actions. Relevant roles include OpenClaw administrators and defenders. Supported consequences include verifying OpenClaw versions, reviewing exec approvals, and monitoring command executions. Evidence limits include limited information on exploitation or affected versions.

  • Verify OpenClaw versions and ensure upgrades to 2026.8.1 or later to prevent directory binding issues
  • Review exec approvals and their usage to prevent unauthorized command executions
  • Monitor for suspicious command executions to detect potential attacks

Technical summary

OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. This vulnerability allows attackers with an allow-always approval to reuse it to run the same command against unreviewed files or repositories with materially different effects. The vulnerability affects OpenClaw deployments, and defenders should prioritize verifying OpenClaw versions and ensuring upgrades to 2026.8.1 or later, reviewing exec approvals and their usage, and monitoring for suspicious command executions.

Defensive priority

Defenders should prioritize verifying OpenClaw versions and ensuring upgrades to 2026.8.1 or later, reviewing exec approvals and their usage, and monitoring for suspicious command executions.

Recommended defensive actions

  • Verify OpenClaw versions and ensure upgrades to 2026.8.1 or later
  • Review exec approvals and their usage
  • Monitor for suspicious command executions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or affected versions is limited. OpenClaw versions before 2026.8.1 are affected, and defenders should verify OpenClaw deployments, review exec approvals, and monitor command executions. Evidence limits include limited information on exploitation or affected versions, and defenders should exercise caution when verifying affected scope.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100530 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100530

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100530 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100530

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.