Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-100586

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Sep 26, 2026
Vendor unknown

Description

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.

References