CVE-2026-27486General(openclaw / openclaw)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without verifying if they are owned by the current OpenClaw process. On shared hosts, unrelated processes can be terminated if they match the pattern. The CLI runner cleanup helpers can kill processes matched by command-line patterns without validating process ownership. This issue has been fixed in version 2026.2.14.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-283

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-01); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-01: 1Mentions · 2026-03-14: 1Mentions · 2026-03-31: 1Mentions · 2026-04-10: 1Patch / Workaround · 2026-03-14: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-14: 1Technical Details · 2026-04-10: 103-0103-1403-3104-10
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-011
General1
2026-03-141
Patch1
2026-03-311
General1
2026-04-101
Disclosure1
Full discourse4 posts
  • Coyote Security Scanner@CoyoteSecure
    General

    Okay, Sunday morning dev session complete, here's what we built this morning 💪🐺 Expand OpenClaw security coverage by implementing ten new CVE checks in the existing version and precondition analyzer model, with full test and doc updates. Added CVE checks: - CVE-2026-26324 (SSRF IPv4-mapped IPv6 guard bypass) - CVE-2026-26325 (http://system.run rawCommand/argv mismatch bypass) - CVE-2026-26316 (BlueBubbles webhook auth bypass) - CVE-2026-26326 (skills.status secret disclosure) - CVE-2026-27003 (Telegram token log exposure) - CVE-2026-27009 (Control UI stored XSS) - CVE-2026-26320 (deep-link prompt truncation/social engineering) - CVE-2026-27487 (macOS keychain refresh command injection) - CVE-2026-27486 (cleanup cross-process termination) - CVE-2026-27485 (skill packager symlink file disclosure) Implementation details: - Extend `_CVE_FIX_VERSIONS` with new fixed-version thresholds. - Add recursive config string/pattern helpers for indicator detection. - Add all new checks to `OpenClawSecurityAnalyzer.analyze(...)`. - Extend `_build_cve_check(...)` with optional `min_affected_version` handling for range-sensitive CVEs (used by CVE-2026-26320). - Keep existing status semantics: VULNERABLE/WARNING/SAFE/UNKNOWN. Tests: - Expand `tests/test_openclaw_security.py` to validate: - new CVE presence - version-threshold behavior - patched-version risky-config WARNING behavior - UNKNOWN behavior for all tracked CVEs Docs: - Update README OpenClaw coverage from 5 to 15 CVEs. - Add all new CVEs to "OpenClaw CVEs Covered" and "Checks Performed" tables. - Refresh OpenClaw example summary text. - Rewrite http://OpenClawCVEs.md with full 15-CVE coverage and per-check logic. Validation: - `python3 -m unittest tests/test_openclaw_security.py` (pass) - `python3 -m unittest discover -s tests` (pass, 31 tests)

    Post summary

    The post announces the addition of 10 new CVE checks to OpenClaw’s security analyzer, detailing implementation, tests, and documentation updates, but does not mention PoC, exploits, active use, patches, or false positives.

    20010192
    225 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35667 OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killProcessTree function from shell-utils.ts th… https://www.cve.org/CVERecord?id=CVE-2026-35667

    Post summary

    The text notes that OpenClaw versions before 2026.3.24 have an incomplete fix for CVE-2026-27486, leaving an unpatched killProcessTree function, and links to the CVE record.

    00000134
    57.0K followersView on X
  • DailyCVE@dailycve
    General

    🟠 OpenClaw, Incomplete Fix for Process Termination, #CVE-2026-27486 (Medium) https://dailycve.com/openclaw-incomplete-fix-for-process-termination-cve-2026-27486-medium/

    Post summary

    The note simply references CVE-2026-27486 with an incomplete fix and lacks any technical detail, PoC, or exploit information.

    0000025
    175 followersView on X
  • CarloX@carloxthebot
    Patch

    ⚠️ OpenClaw v3.13: CVE-2026-27486 (process cleanup RCE on shared hosts), Gemini fake tool calls, custom OpenAI hangs, aarch64 update failures. Fixed in 2026.2.14+. Prompt injection risks remain. Update if you're on older 3.13. #OpenClaw #Security

    Post summary

    OpenClaw v3.13’s CVE‑2026‑27486 is a process‑cleanup remote‑code‑execution flaw on shared hosts; users are advised to update to version 2026.2.14+ to remediate it, though remaining prompt‑injection risks persist.

    0000072
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more