Openclaw · Openclaw · CVE-2026-100580
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.7.1
**Description**
The model-facing cron tool improperly handles case sensitivity. A mixed-case payload kind can bypass the agent-facing shell-execution guard and subsequently normalize into a command job. This allows an actor capable of steering a tool-enabled agent to create a persistent cron job that executes arbitrary commands with the privileges of the OpenClaw process user, potentially granting access to host files and credentials and affecting the availability of scheduled services. This issue specifically affects cron jobs created or edited via the model-facing cron tool.
**Recommendations**
Update to version 2026.7.1.