CVE-2026-100529
7.4
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter interpretation and node display name reuse to access sibling paths or different nodes beyond the operator's original approval scope.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenClaw | OpenClaw | 0 < 2026.8.1 | affected |
| OpenClaw | OpenClaw | 2026.8.1 | unaffected |
Weaknesses
- CWE-863: Incorrect Authorization
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-7jfq-rmfm-29wp
- https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-authorization-scope-widening-via-file-transfer
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.