CVE-2026-101882
Beschrijving NL
OpenClaw Windows Node vóór 2026.7.1 bevat een onvolledige validatiekwetsbaarheid in system.execApprovals.set die wildcard-uitvoerbare regels en misbruikbare systeembinaire bestanden zoals mshta, rundll32 en certutil accepteert. Externe bellers kunnen brede regels toevoegen om willekeurige opdrachten op de Windows-host uit te voeren via system.run zonder operatorcontroles of gebruikersprompts.
Origineel (Engels) tonen
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.