PT-2026-68409 · Mf Yang · Openclaw-Cn

·

CVE-2026-19006

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mf-yang openclaw-cn version 2026.2.5
Description An issue exists in the Ggateway Exec Approval Flow component within the file src/agents/bash-tools.exec.ts. Remote manipulation of this component can lead to incorrect authorization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19006

Affected Products

Openclaw-Cn