OpenClaw Windows 节点在 2026.7.1 版本之前存在一个不完整的验证漏洞,该漏洞位于 接口中。此接口接受通配符可执行文件规则,并允许滥用诸如 、 和 等系统二进制文件。远程调用者可以利用该漏洞添加宽泛的允许规则,从而通过 在 Windows 主机上执行任意命令,且无需经过操作员检查或用户提示。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenClaw | OpenClaw Windows Node | 0 ~ 2026.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101880 | 8.8 HIGH | OpenClaw Windows Node before 2026.7.1 Authorization Bypass |
| CVE-2026-101884 | 7.5 HIGH | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override |
| CVE-2026-101879 | 6.5 MEDIUM | OpenClaw Windows Node before 2026.7.1-3 Missing Authorization |
| CVE-2026-101881 | 6.5 MEDIUM | OpenClaw Windows Node before 2026.7.1 Denial of Service |
| CVE-2026-101883 | 5.4 MEDIUM | OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present |
No comments yet