CVE-2026-28466

CRITICAL EPSS 33.7%
Published Mar 5, 20263mo ago · Modified Jun 17, 20261w ago
9.4 CVSS 4.0
Critical
Find Similar
Published Mar 5, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attackers with valid gateway credentials can inject approval control fields to execute arbitrary commands on connected node hosts, potentially compromising developer workstations and CI runners.

CVSS Details

Base Score
9.4
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
33.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-863 Incorrect Authorization Authorization

Affected Products 1

VendorProductVersionRange
openclawopenclaw* <2026.2.14

References 6

  • github.com https://github.com/openclaw/openclaw/commit/0af76f5f0e93540efbdf054895216c398692afcd
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/318379cdb8d045da0009b0051bd0e712e5c65e2d
    Broken Link
  • github.com https://github.com/openclaw/openclaw/commit/a7af646fdab124a7536998db6bd6ad567d2b06b0
    Broken Link
  • github.com https://github.com/openclaw/openclaw/commit/c1594627421f95b6bc4ad7c606657dc75b5ad0ce
    Broken Link
  • github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-gv46-4xfq-jv58
    MitigationVendor Advisory
  • vulncheck.com https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-node-invoke-approval-bypass
    Third Party Advisory

Remediation

  • github.com https://github.com/openclaw/openclaw/commit/0af76f5f0e93540efbdf054895216c398692afcd
    Patch