CVE-2026-22176Disclosure(openclaw / openclaw)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to gateway.cmd using unquoted set KEY=VALUE assignments, allowing shell metacharacters to break out of assignment context. Attackers can inject arbitrary commands through environment variable values containing metacharacters like &, |, ^, %, or ! to achieve command execution when the scheduled task script is generated and executed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-19); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-19: 3Mentions · 2026-03-21: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-21: 103-1903-21
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-193
Disclosure2General1
2026-03-211
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-22176 📊 Severity: 6.1 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-22176 #CVE-2026-22176 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/nqvDPyT3Fc

    Post summary

    The tweet merely highlights CVE-2026-22176 with basic severity and impact metrics but provides no actionable details, exploitation evidence, or mitigation steps.

    0000023
    108 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-22176 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-22176-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-22176 #openclaw #

    Post summary

    The post is a brief alert announcing CVE‑2026‑22176 for OpenClaw, but it provides no technical details, PoC, or evidence of exploitation.

    0000078
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22176 Command Injection Vulnerability in OpenClaw Scheduled Task Script Generation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22176

    Post summary

    The text announces a command injection vulnerability in OpenClaw's scheduled task script generation, providing minimal technical detail but no evidence of exploitation, PoC, patch, or false‑positive claims.

    0000048
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22176 OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to … https://www.cve.org/CVERecord?id=CVE-2026-22176

    Post summary

    The entry announces a command injection vulnerability (CVE‑2026‑22176) in OpenClaw versions pre‑2026.2.19, affecting Windows Scheduled Task script generation, with no PoC, exploit, or patch details provided.

    00000110
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more