← Back to search

CVE-2026-100586

8.8 HIGHpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows non-owner channel senders with command access to create bindings to the native Codex runtime, enabling them to execute host-capable actions with access to sensitive files, tools, and processes.
Exploitability
Exploitation is moderately hard due to the need for command access and specific authorization conditions. Precondition is the presence of non-owner channel senders with command access.
Blast radius
If exploited, the impact could be severe, potentially leading to unauthorized access to critical files, tools, and processes on the host system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to OpenClaw Codex 2026.7.1 or later.
rceauth-bypasscode-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-269

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.