{"id":"CVE-2026-100596","published":"2026-09-26T03:17:08.187","lastModified":"2026-09-28T15:18:41.260","description":"OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-wwx7-573h-pqwc","tags":[]},{"url":"https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-authorization-bypass-via-mcp-configuration","tags":[]}],"exploitRefs":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-wwx7-573h-pqwc","tags":[]}],"hasPoc":true,"ai":{"summary":"OpenClaw versions before 2026.7.1 allow non-owner users to execute arbitrary stdio MCP commands with process privileges, leading to potential host compromise.","exploitability":"Exploitation is relatively straightforward as it requires non-owner user access to the /mcp set and /mcp unset commands.","blast_radius":"If exploited, this flaw could result in significant host confidentiality, integrity, and availability issues.","remediation":"Upgrade to OpenClaw 2026.7.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","privilege-escalation","configuration","mcp"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:01:25.406Z"}}