Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 10 min 124 bronnen 3 kritiek 6 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-101882

HIGH · 8.8 CVSS Gepubliceerd: CWE-184

Beschrijving NL

OpenClaw Windows Node vóór 2026.7.1 bevat een onvolledige validatiekwetsbaarheid in system.execApprovals.set die wildcard-uitvoerbare regels en misbruikbare systeembinaire bestanden zoals mshta, rundll32 en certutil accepteert. Externe bellers kunnen brede regels toevoegen om willekeurige opdrachten op de Windows-host uit te voeren via system.run zonder operatorcontroles of gebruikersprompts.

Origineel (Engels) tonen

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.

References