CVE-2026-101882

Source
https://cve.org/CVERecord?id=CVE-2026-101882
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101882.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101882
Related
Published
2026-09-30T19:16:03Z
Modified
2026-10-02T03:47:08Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
Details

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-184"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101882.json"
}
References

Affected packages

Git / github.com/openclaw/openclaw-windows-node

Affected ranges

Type
GIT
Repo
https://github.com/openclaw/openclaw-windows-node
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2026.7.1"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.2.0
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.5.0
v0.6.0
v0.6.0-alpha.1
v0.6.0-alpha.10
v0.6.0-alpha.11
v0.6.0-alpha.12
v0.6.0-alpha.13
v0.6.0-alpha.14
v0.6.0-alpha.15
v0.6.0-alpha.2
v0.6.0-alpha.3
v0.6.0-alpha.4
v0.6.0-alpha.5
v0.6.0-alpha.6
v0.6.0-alpha.7
v0.6.0-alpha.9
v0.6.1
v0.6.11
v0.6.12
v0.6.2
v0.6.2-alpha.1
v0.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101882.json"