Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Shayd-Versa

#31315of 57,623
8.8Total CVSS
Vulnerabilities · 1
PT-2026-99216
8.8
2026-09-26
Openclaw · Openclaw · CVE-2026-100580
**Name of the Vulnerable Software and Affected Versions** OpenClaw versions prior to 2026.7.1 **Description** The model-facing cron tool improperly handles case sensitivity. A mixed-case payload kind can bypass the agent-facing shell-execution guard and subsequently normalize into a command job. This allows an actor capable of steering a tool-enabled agent to create a persistent cron job that executes arbitrary commands with the privileges of the OpenClaw process user, potentially granting access to host files and credentials and affecting the availability of scheduled services. This issue specifically affects cron jobs created or edited via the model-facing cron tool. **Recommendations** Update to version 2026.7.1.