Skip to main content
Vulnerability Database/CVE-2026-100573

CVE-2026-100573: OpenClaw MCP Auth Bypass Vulnerability

CVE-2026-100573 is an authentication bypass flaw in OpenClaw that allows sandboxed sessions to invoke explicitly denied tools through the MCP loopback component. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-100573 Overview

CVE-2026-100573 is a sandbox policy bypass vulnerability in OpenClaw versions before 2026.8.1. The flaw resides in the Model Context Protocol (MCP) loopback component. Sandboxed coding-agent sessions can enumerate and invoke tools that administrators explicitly denied through the sandbox.tools.deny policy. The weakness is classified as [CWE-862] Missing Authorization.

Attackers with local, low-privileged access to a sandboxed session can reach data or trigger actions the operator intended to exclude. The issue affects confidentiality within the sandbox boundary but does not directly impact integrity or availability.

Critical Impact

Sandboxed coding-agent sessions can bypass sandbox.tools.deny controls and invoke prohibited MCP tools, breaking the operator's intended isolation boundary.

Affected Products

  • OpenClaw versions prior to 2026.8.1
  • OpenClaw MCP loopback component
  • Deployments relying on sandbox.tools.deny policy enforcement

Discovery Timeline

  • 2026-09-26 - CVE-2026-100573 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100573

Vulnerability Analysis

OpenClaw sandboxes coding-agent sessions and restricts tool access using a policy file. The sandbox.tools.deny directive lists MCP tools that must not be exposed to the agent. The MCP loopback component fails to apply this deny list when the sandboxed session issues tool-listing or tool-invocation requests through the loopback channel.

As a result, an agent operating inside the sandbox can discover the full tool catalog and call entries the operator intended to block. The vulnerability is scoped to local attack surface, requires low privileges, and needs no user interaction. Impact is limited to confidentiality of data reachable through the denied tools.

Root Cause

The root cause is missing authorization enforcement in the MCP loopback request handler. The handler consults the sandbox session context but does not evaluate requests against the sandbox.tools.deny policy before resolving tool references or dispatching tool calls. Policy enforcement is applied on one request path but omitted on the loopback path, producing an inconsistent authorization model.

Attack Vector

An attacker who controls prompts, inputs, or code executed inside a sandboxed OpenClaw coding-agent session can issue MCP requests through the loopback interface. The attacker first calls the tool-listing endpoint to enumerate available tools, including those on the deny list. The attacker then invokes a denied tool directly through loopback to perform the restricted action or exfiltrate data accessible to that tool.

No authentication bypass or network access is required. The attack surface is limited to parties who can influence execution within an existing sandboxed session. See the GitHub Security Advisory GHSA-5m4g-88rg-69pj and the VulnCheck Advisory on OpenClaw for additional technical context.

Detection Methods for CVE-2026-100573

Indicators of Compromise

  • MCP loopback requests from sandboxed sessions targeting tools listed in sandbox.tools.deny
  • Tool-listing responses returning entries that should be filtered by policy
  • Unexpected invocations of privileged or external-access tools from coding-agent sessions

Detection Strategies

  • Log every MCP loopback request with session identifier, requested tool name, and policy decision
  • Compare observed tool invocations against the configured sandbox.tools.deny list and alert on mismatches
  • Baseline normal tool usage per project or agent profile and flag deviations

Monitoring Recommendations

  • Forward OpenClaw sandbox and MCP loopback logs to a centralized analytics platform for correlation
  • Alert on first-time use of sensitive tools (filesystem, network, shell) by any sandboxed session
  • Review audit trails for enumeration patterns such as repeated tool-listing calls followed by denied-tool invocations

How to Mitigate CVE-2026-100573

Immediate Actions Required

  • Upgrade OpenClaw to version 2026.8.1 or later on all hosts running coding-agent sandboxes
  • Inventory existing sandbox policies and identify any sandbox.tools.deny entries that may have been bypassed
  • Rotate credentials, tokens, or API keys that any denied tool could have accessed from a sandboxed session

Patch Information

The fix is included in OpenClaw 2026.8.1. Refer to the GitHub Security Advisory GHSA-5m4g-88rg-69pj for release notes and remediation guidance. The patched release enforces sandbox.tools.deny consistently across both standard and MCP loopback request paths.

Workarounds

  • Restrict MCP loopback exposure to trusted components only, where feasible
  • Remove sensitive tools from the sandbox entirely rather than relying solely on the deny list until patched
  • Limit which users or processes can start sandboxed OpenClaw sessions to reduce local attack surface
bash
# Verify installed OpenClaw version and upgrade
openclaw --version

# Upgrade to the patched release
pip install --upgrade "openclaw>=2026.8.1"

# Validate sandbox policy enforcement after upgrade
openclaw sandbox policy validate --config /etc/openclaw/sandbox.yaml

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.