CVE-2026-42423

7.5

OpenClaw · OpenClaw

OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements, allowing for unauthorized inline command execution.

Executive summary

A security flaw in OpenClaw before version 2026.4.8 allows authenticated attackers to bypass critical command execution approval requirements, posing a significant risk to system integrity.

Vulnerability

The vulnerability, categorized as CWE-636 (Not Failing Securely), stems from an approval-timeout fallback mechanism on gateway and node execution hosts. Authenticated users can exploit this behavior to bypass explicit-approval requirements for strictInlineEval commands, effectively circumventing intended security boundaries.

Business impact

The ability for an authenticated attacker to execute arbitrary inline evaluation commands without authorization threatens the overall integrity of the environment. Given the CVSS score of 7.5, this vulnerability represents a high risk, as it allows for unauthorized code execution that could lead to full system compromise or lateral movement within the infrastructure.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.4.8 or later immediately to resolve the approval-timeout bypass.

Proactive Monitoring: Review system and gateway logs for unauthorized execution attempts or anomalies related to inline evaluation commands originating from standard user accounts.

Compensating Controls: Ensure that network security policies restrict access to gateway and node management interfaces to authorized personnel only, limiting the pool of potential attackers who could exploit this flaw.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a high risk to environment security by allowing authenticated users to elevate their capabilities through command execution bypasses. Organizations should prioritize updating to version 2026.4.8 immediately to ensure that strictInlineEval approval requirements are enforced correctly and consistently.

More OpenClaw CVEs

Sources

Originally found and disclosed by zsx (@zsxsoft), KeenSecurityLab, per the CVE Program record.