Incorrect authorization in OpenClaw - CVE-2026-27566
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass intended allowlist restrictions and execute non-allowlisted commands.
The vulnerability exists due to incorrect authorization in system.run exec allowlist analysis when processing requests that route execution through env or shell-dispatch wrapper binaries. A remote user can submit a specially crafted system.run request to bypass intended allowlist restrictions and execute non-allowlisted commands.
Exploitation requires the ability to trigger system.run requests under an allowlist policy.