OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-101880

HIGH · CVSS 8.8 EPSS 0.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An incorrect authorization vulnerability in OpenClaw Windows Node allows connected gateways or agents to bypass execution approval rules, leading to arbitrary command execution on affected Windows systems. This flaw arises from the failure to properly parse commands using pipe operators or command substitutions, which can be exploited to execute unauthorized commands. Organizations utilizing OpenClaw on Windows should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101880
Severity
HIGH
CVSS
8.8
EPSS
0.69%
Windows

Original NVD Description

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.