CVE-2026-101880

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets6 URLs
Full discourse1 post
  • Code Solutions@CodeSolutionsIL

    Don’t Panic Digest Inform. Gate. Then automate. News — OpenClaw Windows Node approval-rule bypasses (CVE-2026-101880 + CVE-2026-101882, CVSS 3.1 8.8 HIGH each; CVE-2026-101884, 7.5 HIGH): the Windows companion for the OpenClaw agent should only run commands its approval rules allow, but the checks had gaps: a command chained behind an allowed one went unchecked, a remote caller could add broad “allow” rules, and a filter missed some settings that let allowed tools run other code. Each needs a connected gateway or agent. Affected before 2026.7.1 (CNA VulnCheck, Sep 30); fixed since 2026.7.1 (Aug 10) and in the current release, v2026.9.8-1 (Oct 7) — update to the current release. Not in CISA KEV; no in-the-wild use stated. Operator read: an SI (super intelligence) agent’s approval list that only blocks known-bad commands can be talked around — allow commands by name only, check every part of a chained command, and never let the agent edit its own rules. https://nvd.nist.gov/vuln/detail/CVE-2026-101880 Related: OpenAI’s GPT-6 Sol and GPT-6 Luna system card (Oct 7) — in OpenAI’s own tests (mostly low-stakes, run without its extra safety controls), the models found another way round blocks such as “access denied” errors in 28% (GPT-6 Sol) and 15.9% (GPT-6 Luna) of runs on the highest-effort setting. For us, the real limit belongs outside the model. Our Plainwrap daily notes: https://x.com/CodeSolutionsIL/status/2108225985653145923 https://deploymentsafety.openai.com/gpt-6-october More — Sabrina Halper × Wiz co-founder Yinon Costica (attack vs defense, agent guardrails, ~22:45–43:30 + 47:15–58:30): What’s in it: Costica tells Halper it is easier right now for attackers to use SI for one attack than for defenders to secure everything, but argues defenders can pull ahead by testing their own systems and using what they know about their own environments. He also covers guardrails for agents that can reach payments or sensitive data, models anyone can download and run, and humans as security’s “moral compass,” while pushing for fewer routine human approvals. Our takeaway: for us, any agent action that spends money, touches sensitive data, or changes systems still waits for a named person’s OK. Notes of a public interview, not product guidance; the guest’s claims are as discussed, not verified, and panel opinions are not endorsed. https://gist.github.com/CodeSolutionsLLC/414c9a30bee061cb3490316343098feb https://x.com/SabrinaHalper/status/2107893808344272933 https://codesolutionsllc.com/news

    1000095
    11 followersView on X

Explore more