HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-100596 — OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users exe...

·Source: NIST NVD

Updated:

Executive Summary

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

Analysis

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability. CVSS Score: 8.8. Published: 2026-09-26T03:17:08.187.

Indicators of Compromise (1)

CVE (1)
CVE-2026-100596
Source Attribution

Originally published by NIST NVD on Sep 26, 2026. Verified by: NIST.

Related Threats