PatchSiren cyber security CVE debrief
CVE-2026-100552 OpenClaw CVE debrief
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. When a lower-trust conversation was assigned to a Codex runtime and restricted with a per-chat tool allowlist, a participant able to trigger that agent could still reach native command and file tools, bypassing the configured allowlist.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for OpenClaw deployments, particularly those using Codex runtime, should assess exposure and verify configurations to prevent potential policy bypass. This includes reviewing Codex runtime configurations, verifying OpenClaw version, and ensuring proper enforcement of per-chat tool policies. Additionally, defenders should monitor for potential exploitation attempts and review system logs for suspicious activity.
Why it matters
Defenders should care about CVE-2026-100552 because it allows participants to bypass configured allowlists and access native command and file tools in OpenClaw before version 2026.8.1, potentially leading to unauthorized access and privilege elevation.
- Potential unauthorized access to native command and file tools
- Possible elevation of privileges
- Bypassing of configured allowlists
- Verification of OpenClaw version and Codex runtime configurations required
Technical summary
OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process, file, and patch tools owned by the Codex runtime. This oversight allows participants to bypass configured allowlists and access native command and file tools, potentially leading to unauthorized access and privilege elevation. The issue is fixed in version 2026.8.1, which correctly enforces per-chat tool policies.
Defensive priority
Defenders should prioritize verifying and upgrading to OpenClaw version 2026.8.1 or later, and review Codex runtime configurations to ensure proper enforcement of per-chat tool policies.
Recommended defensive actions
- Verify OpenClaw version and upgrade to 2026.8.1 or later
- Review Codex runtime configurations to ensure proper enforcement of per-chat tool policies
- Monitor for potential exploitation attempts
- Perform vulnerability scanning to identify potentially exposed systems
- Review system logs for suspicious activity
- Implement additional compensating controls to mitigate potential risks
- Track and document remediation efforts
Evidence notes
The CVE record and source references provide details on the vulnerability in OpenClaw before version 2026.8.1. The issue is fixed in version 2026.8.1. Defenders should verify OpenClaw version and Codex runtime configurations to ensure proper enforcement of per-chat tool policies. Evidence is limited to CVE and source references; further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100552 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100552
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100552 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100552
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-wwcw-jfpp-gpxw
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-policy-bypass-via-native-tools
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.