Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes. | |
| Title | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T02:19:10.286Z
Reserved: 2026-09-26T01:04:14.442Z
Link: CVE-2026-100586
No data.
Status : Received
Published: 2026-09-26T03:17:06.660
Modified: 2026-09-26T03:17:06.660
Link: CVE-2026-100586
No data.
OpenCVE Enrichment
No data.
-
CWE-269
Improper Privilege Management