Incorrect authorization in OpenClaw - CVE-2026-29607
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to incorrect authorization in execution approval persistence flows when approving wrapped system.run commands with allow-always in security=allowlist mode. A remote privileged user can approve a benign wrapped invocation and later execute different inner payloads to execute arbitrary commands.
User interaction is required, and the issue affects gateway and node-host execution approval persistence flows.