CVE-2026-100586
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Sep 26, 2026
Vendor
unknown
Description
OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.