PT-2026-99223 · Openclaw · Openclaw

·

CVE-2026-100587

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.7.1
Description Insufficient validation of owner authorization occurs within the Codex computer-use installation command. This allows senders in a channel who are not owners to install arbitrary plugins and execute Model Context Protocol (MCP) processes—a standard for connecting AI models to external data sources—using the privileges of the OpenClaw user. This issue impacts the confidentiality, integrity, and availability of the host system.
Recommendations Update to version 2026.7.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100587
GHSA-PJJR-5QHR-5W6R

Affected Products

Openclaw