CVE-2026-28363Disclosure(openclaw / openclaw)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openclaw openclaw systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-27); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-27: 5Mentions · 2026-02-28: 1Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-27: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-27: 5Technical Details · 2026-02-28: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-04: 102-2702-2803-0203-04
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-275
Disclosure5
2026-02-281
Patch1
2026-03-021
Patch1
2026-03-041
Disclosure1
Full discourse8 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28363: CRITICAL] Beware: OpenClaw security loophole found! Validation bypass in tools.exec.safeBins exposes execution paths without approval. Stay safe by updating before 2026.2.23.#cve,CVE-2026-28363,#cybersecurity https://cvefind.com/CVE-2026-28363

    Post summary

    A critical CVE‑2026‑28363 vulnerability in OpenClaw’s tools.exec.safeBins permits a validation bypass that allows unauthorized code execution. Users are advised to update before 2026.2.23 to patch the issue.

    0010083
    585 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28363 (CVSS:9.9, CRITICAL) is Analyzed. In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation..https://nvd.nist.gov/vuln/detail/CVE-2026-28363 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-28363 is a critical vulnerability in OpenClaw that allows bypassing safeBins validation for sort via GNU long-option abbreviation; no PoC, exploit, or patch details are provided.

    0000042
    173 followersView on X
  • maru@maru1151157
    Patch

    🚨 CVE-2026-28363 (CVSS: 9.9) OpenClaw 2026.2.23以前では、allowlistモードでGNUロングオプションの略称(例: --compress-prog)によりtools.exec.safeBinsの検証がバイパス可能で、承認不要の実行パスが発生。対策: 2026.2.23以降にアップデート。 https://maruomosquit.com/vulnerability/CVE-2026-28363/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-28363 is a high‑severity vulnerability in OpenClaw that allows bypassing safe‑binary checks via abbreviated GNU long options; the issue is fixed in version 2026.2.23 and later.

    00000190
    1.4K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `OpenClaw` is vulnerable to a validation bypass (CVE-2026-28363) via GNU long-option abbreviations in allowlist mode. This could allow unintended circumvention of security controls. Update to `openclaw` version 2026.2.23. #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-28363-openclaw-validation-bypass-gnu-options

    Post summary

    OpenClaw suffers a validation bypass (CVE-2026-28363) that can be mitigated by updating to version 2026.2.23.

    0000057
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28363 In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode,… https://www.cve.org/CVERecord?id=CVE-2026-28363

    Post summary

    A validation bypass in OpenClaw prior to version 2026.2.23 allows sort to be exploited via GNU long-option abbreviations, but no PoC, exploit, or patch is reported.

    00000125
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28363 OpenClaw Privilege Escalation via GNU Long-Option Abbreviation Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28363

    Post summary

    CVE-2026-28363 is a disclosed privilege escalation vulnerability in OpenClaw that exploits a GNU long‑option abbreviation bypass.

    0000051
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-28363** pertains to a validation bypass in the OpenClaw software, specifically in versions prior to 2026.2.23. The core issue involves the `tools.exec.safeBins` validation logic for the `sort` command, which can be bypassed through the use of GNU long-option abbreviations (e.g., `--compress-prog`) in allowlist mode. This bypass allows attackers to execute commands without proper approval, potentially leading to arbitrary command execution. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-28363

    Post summary

    The post discloses a validation bypass in OpenClaw that permits arbitrary command execution via GNU long-option abbreviations.

    0000053
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28363 - Critical In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-... https://www.thehackerwire.com/vulnerability/CVE-2026-28363/ https://t.co/CAm4AE0Psv

    Post summary

    A critical vulnerability in OpenClaw allows bypass of safeBins validation through GNU long-option abbreviations, potentially enabling unauthorized actions.

    0000068
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more