PT-2026-99222 · Unknown · Openclaw Codex

·

CVE-2026-100586

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw Codex versions prior to 2026.7.1
Description Insufficient owner authorization enforcement occurs during the creation of native conversation bindings. This allows non-owner channel senders who possess command access to establish bindings to the native Codex runtime. Consequently, these users can execute host-capable turns, granting them unauthorized access to files, tools, and processes.
Recommendations Update OpenClaw Codex to version 2026.7.1 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100586
GHSA-9P6M-2872-XM7X

Affected Products

Openclaw Codex