CVE-2026-101882

Summary

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.

Affected Software

VendorProductVersion RangeStatus
OpenClawOpenClaw Windows Node0 < 2026.7.1affected

Weaknesses

  • CWE-184: Incomplete List of Disallowed Inputs

References