CVE-2026-100596

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw process privileges when configuration loads, compromising host confidentiality, integrity, and availability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-26: 1Mentions · 2026-09-27: 109-2609-27
Referenced assets1 URL
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli

    🚨 OpenClaw’da 4 yeni High seviye güvenlik açığı OpenClaw'ın 2026.7.1 öncesi sürümlerini etkileyen 4 yeni CVE yayınlandı: 🔸 CVE-2026-100599 | CVSS 8.8 Google Meet node komutları üzerinden approval mekanizmasının bypass edilmesi ve bağlı node üzerinde kod çalıştırılması (RCE). 🔸 CVE-2026-100596 | CVSS 8.8 MCP yapılandırması üzerinden authorization bypass. Kötü amaçlı stdio komutu yapılandırmaya eklenerek kalıcı kod çalıştırma mümkün olabiliyor. 🔸 CVE-2026-100588 | CVSS 8.3 node.invoke üzerinden yetkilendirme kontrolünün aşılması ve bağlı browser node üzerinde yetkisiz işlemler gerçekleştirilmesi. 🔸 CVE-2026-100589 | CVSS 8.8 Sandbox kısıtlamalarının browser üzerinden aşılmasıyla host browser/node kontrolüne erişim sağlanabilmesi. 🛡️ Etkilenen sürümler: OpenClaw < 2026.7.1 ✅ Çözüm: OpenClaw 2026.7.1 veya üzeri sürüme güncelleyin. Özellikle CVE-2026-100599 ve CVE-2026-100596, agent'ın yetkileri üzerinden host üzerinde kod çalıştırma açısından dikkat çekiyor.

    00031405
    2.4K followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — OPENCLAW MCP CONFIGURATION AUTHORIZATION BYPASS September 26, 2026 — CVE assignment surfaced DISCLOSED BY: OpenClaw PRODUCT: OpenClaw MCP configuration CVE: CVE-2026-100596 — vendor GHSA mapping has not yet synchronized and still displays “No known CVE” AFFECTED VERSIONS: < 2026.7.1 IMPACT: An authorized non-owner external-channel sender could persist an attacker-selected stdio MCP command that executes with OpenClaw process-user privileges when MCP configuration loads. EXPLOITATION STATUS: VULNERABILITY CONFIRMED BY VENDOR. No confirmed in-the-wild exploitation established during this check. URGENT ACTION: Upgrade to 2026.7.1+, disable external-channel MCP configuration commands until upgraded, and audit configured MCP servers for unauthorized entries. SOURCE: https://github.com/openclaw/openclaw/security/advisories/GHSA-wwx7-573h-pqwc?utm_source=chatgpt.com #CyberSecurity #AISecurity #AIAgents #OpenClaw #MCP #AgentSecurity #Authorization

    0000061
    222 followersView on X

Explore more