PT-2026-99216 · Openclaw · Openclaw
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.7.1
Description
The model-facing cron tool improperly handles case sensitivity. A mixed-case payload kind can bypass the agent-facing shell-execution guard and subsequently normalize into a command job. This allows an actor capable of steering a tool-enabled agent to create a persistent cron job that executes arbitrary commands with the privileges of the OpenClaw process user, potentially granting access to host files and credentials and affecting the availability of scheduled services. This issue specifically affects cron jobs created or edited via the model-facing cron tool.
Recommendations
Update to version 2026.7.1.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw