CVE-2026-100560 Overview
CVE-2026-100560 is an authorization bypass vulnerability in OpenClaw versions before 2026.8.1. The flaw affects the Allow Always approval mechanism on macOS and Linux. Approvals granted for an exact command persist as path-only grants, ignoring the specific arguments originally authorized. Attackers can reuse the approved executable with arbitrary arguments to run commands without triggering a new approval prompt. This enables unauthorized access to files, internal services, or sensitive operations through a previously trusted binary path. The vulnerability is tracked under CWE-863: Incorrect Authorization.
Critical Impact
Attackers can abuse persistent path-only approvals to execute arbitrary commands under a trusted executable, bypassing the OpenClaw approval workflow entirely.
Affected Products
- OpenClaw versions prior to 2026.8.1
- macOS deployments of OpenClaw
- Linux deployments of OpenClaw
Discovery Timeline
- 2026-09-26 - CVE-2026-100560 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100560
Vulnerability Analysis
OpenClaw's approval model is designed to let users authorize specific commands through an Allow Always decision. Users expect that approval to bind the exact command, including arguments. In vulnerable versions, the approval is stored as a path-only grant on macOS and Linux. Any subsequent invocation of that executable, regardless of arguments, matches the stored grant and proceeds without a new prompt. The vulnerability falls under CWE-863: Incorrect Authorization because the authorization check does not reflect the originally approved operation.
Root Cause
The root cause is a mismatch between what the user authorizes and what the system persists. The approval UI references an exact command with arguments. The persistence layer discards the argument context and keeps only the executable path. This grants broader authority than the user intended and converts a narrow approval into a reusable execution primitive.
Attack Vector
An attacker who can influence prompts, workflows, or orchestration logic that invokes OpenClaw commands can reuse any previously approved binary path with different arguments. For example, an executable approved to list a specific directory can later be invoked to read sensitive files or reach internal services. Exploitation requires user interaction to establish the initial Allow Always grant, after which the bypass is silent. See the GitHub Security Advisory GHSA-74gc-hg2m-79p9 and the VulnCheck Advisory on OpenClaw for additional technical context.
No verified proof-of-concept code is published for this issue. The vulnerability is described in prose by both the GitHub Security Advisory and the VulnCheck advisory referenced above.
Detection Methods for CVE-2026-100560
Indicators of Compromise
- Repeated invocations of the same approved executable path with varied or unexpected argument sets.
- Approved binaries accessing file paths or network endpoints that fall outside their original approved scope.
- OpenClaw audit entries showing command executions without a corresponding user approval prompt.
Detection Strategies
- Review OpenClaw approval records and compare each stored grant against the exact commands users intended to approve.
- Correlate process execution telemetry with OpenClaw approval events to flag commands that run under an existing grant with new arguments.
- Hunt for sensitive file reads or internal service connections initiated by executables previously approved for narrower tasks.
Monitoring Recommendations
- Enable process command-line logging on macOS and Linux hosts running OpenClaw.
- Forward OpenClaw approval and execution logs to a centralized log platform for retention and correlation.
- Alert on first-seen argument combinations for executables that already have an Allow Always grant.
How to Mitigate CVE-2026-100560
Immediate Actions Required
- Upgrade OpenClaw to version 2026.8.1 or later on all macOS and Linux endpoints.
- Revoke existing Allow Always approvals and re-issue them only after upgrading to a fixed version.
- Audit historical executions tied to previously approved binaries for unauthorized argument usage.
Patch Information
The issue is fixed in OpenClaw 2026.8.1. Patch details and release notes are published in the GitHub Security Advisory GHSA-74gc-hg2m-79p9. The VulnCheck Advisory on OpenClaw also tracks fix availability and affected version ranges.
Workarounds
- Avoid using Allow Always for commands that accept argument-controlled file paths, URLs, or hostnames until upgraded.
- Prefer per-invocation approvals so each command execution is explicitly reviewed.
- Restrict which executables are reachable from OpenClaw by tightening operating system permissions on sensitive binaries.
# Verify installed OpenClaw version meets the fixed release
openclaw --version
# Expected output: 2026.8.1 or later
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.