CVE-2026-31992Disclosure(openclaw / openclaw)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows authenticated operators to execute unintended commands. When /usr/bin/env is allowlisted, attackers can use env -S to bypass policy analysis and execute shell wrapper payloads at runtime.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-20: 1Technical Details · 2026-03-19: 303-1903-20
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure3General1
2026-03-201
General1
Full discourse5 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-31992 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-31992-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-31992 #openclaw #

    Post summary

    The post serves as a brief CVE alert providing a link to external details, but it offers no substantive information on the vulnerability, its exploitation, or remediation within the text.

    0000188
    3.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-31992 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31992 #CVE-2026-31992 #CVE #High  #CyberSecurity #InfoSec https://t.co/3WuwD7rsHj

    Post summary

    The tweet announces CVE‑2026‑31992 with a severity score of 7.1, but it provides no technical details, exploit code, or patch information.

    0000030
    108 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    🚨 6 high-severity CVEs dropped today for OpenClaw - the popular AI automation platform CVE-2026-28461 (7.5) - Memory exhaustion via webhook CVE-2026-31989 (7.4) - SSRF via web_search CVE-2026-27566 (7.1) - Allowlist bypass CVE-2026-31992 (7.1) - Exec-guard bypass CVE-2026-31994 (7.1) - Command injection CVE-2026-31998 (7.0) - Auth bypass Popular platforms = bigger targets. Track everything: http://vulntracker.io

    Post summary

    The post announces the disclosure of six high‑severity CVEs affecting OpenClaw’s AI automation platform, providing brief vulnerability descriptors but no evidence of active exploitation or available patches.

    00000124
    433 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31992 OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in http://system.run guardrails that allows authenticated operators to execute unintended comm… https://www.cve.org/CVERecord?id=CVE-2026-31992

    Post summary

    The CVE-2026-31992 entry notes an allowlist bypass in OpenClaw’s system.run guardrails, impacting versions before 2026.2.23 and permitting authenticated operators to run unintended commands.

    0000091
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31992 OpenClaw Allowlist Bypass Vulnerability Enables Unauthorized Command Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31992

    Post summary

    A new OpenClaw allowlist bypass vulnerability (CVE‑2026‑31992) that permits unauthorized command execution has been reported, but no PoC, exploit details, patches, or evidence of active exploitation are provided.

    0000052
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more