{"id":"CVE-2026-100586","published":"2026-09-26T03:17:06.660","lastModified":"2026-09-28T20:17:07.507","description":"OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-269"],"vendors":[],"products":[],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-9p6m-2872-xm7x","tags":[]},{"url":"https://www.vulncheck.com/advisories/openclaw-codex-before-2026.7.1-authorization-bypass-via-bind","tags":[]}],"exploitRefs":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-9p6m-2872-xm7x","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows non-owner channel senders with command access to create bindings to the native Codex runtime, enabling them to execute host-capable actions with access to sensitive files, tools, and processes.","exploitability":"Exploitation is moderately hard due to the need for command access and specific authorization conditions. Precondition is the presence of non-owner channel senders with command access.","blast_radius":"If exploited, the impact could be severe, potentially leading to unauthorized access to critical files, tools, and processes on the host system.","remediation":"Upgrade to OpenClaw Codex 2026.7.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:07:31.108Z"}}