CVE-2026-100586

8.8

Codex · OpenClaw

OpenClaw Codex before 2026.7.1 fails to enforce owner authorization for native conversation bindings, allowing authenticated users to execute host-capable commands.

Executive summary

A critical authorization bypass in OpenClaw Codex allows authenticated users to execute host-capable commands and gain unauthorized access to system resources.

Vulnerability

The application fails to properly enforce owner authorization when creating native conversation bindings. This allows non-owner channel senders with command access to interact with the native Codex runtime and execute host-capable turns, resulting in unauthorized access to files, tools, and processes.

Business impact

With a CVSS score of 8.8, this vulnerability represents a high risk of privilege escalation and unauthorized system interaction. Successful exploitation allows a malicious actor to escape intended security boundaries, potentially resulting in the compromise of sensitive host-level data or unauthorized manipulation of system processes.

Remediation

Immediate Action: Update OpenClaw Codex to version 2026.7.1 or later, which introduces mandatory admin authority for node approvals and restricts unsafe environment overrides.

Proactive Monitoring: Review audit logs for unusual conversation binding requests or unauthorized attempts to access host tools and processes by non-owner accounts.

Compensating Controls: Enforce strict access control policies for channel senders and limit command-line access to the Codex runtime until the security update is fully deployed across all nodes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability highlights the risk of improper privilege management within runtime environments. Administrators must upgrade to version 2026.7.1 to ensure that native conversation bindings are correctly gated by owner authorization, thereby preventing lateral movement and unauthorized host-level execution.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief high section

Sources

Originally found and disclosed by wwwvwwvwwwwwvwwvw, per the CVE Program record.