CVE-2026-43530Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allows attackers to obscure which applet would actually run. Attackers can exploit opaque multi-call binaries to bypass exec approval mechanisms and weaken risk classification of unsafe applet invocations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 105-0505-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 7 ثغرات خطيرة في OpenClaw! ⚠️ الثغرتين الأخطر ممكن تستغل بدون صلاحيات (Unauthenticated): (CVE-2026-43534) | تقييم 9.3 تخلي بيانات خارجية (External hook metadata) تعامل كأنها أوامر داخلية موثوقة للنظام و ثد تنتقل إلى سياق أعلى ثقة داخل الـ agent بدون تدخل من المستخدم. (CVE-2026-43566) | تقييم 9.1 المخترق يرسل (Webhook) من مصدر غير موثوق، ويتجاوز نظام الصلاحيات ليتنفذ الأمر كأنه من مالك النظام نفسه! ⚙️ الخمس ثغرات الباقية تحتاج صلاحيات منخفضة للاستغلال وكلها بتقييم 8.8: (CVE-2026-43571): إضافة خبيثة تنزل مكان الإضافة الرسمية بسبب خلل في ترتيب البحث وتتجاوز أدوات التحقق. (CVE-2026-43569): إضافة غير موثوقة تتفعل تلقائياً وقت الإعداد الأولي (Onboarding) بدون إذن المستخدم. (CVE-2026-43530): استخدام أدوات مجمعة مثل (busybox) يخلي المخترق يموّه الأوامر. النظام يوافق على أمر آمن ظاهرياً لكن اللي يتنفذ فعلياً أمر خبيث. (CVE-2026-42435): حقن متغيرات حساسة في الشل (مثل SHELLOPTS) على مستوى (argv) وتجاوز الفحص قبل التنفيذ. (CVE-2026-42434): هروب الوكيل من الـ Sandbox. 🛡️ حدّث فوراً لإصدار (2026.4.14).

    Post summary

    This post announces seven new high‑severity CVEs for OpenClaw, detailing their exploitation mechanisms and CVSS scores. It recommends updating to version 2026.4.14 to remediate the issues.

    03016102.5K
    49.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43530 OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allows attackers to ob… https://www.cve.org/CVERecord?id=CVE-2026-43530

    Post summary

    The text discloses CVE-2026-43530, noting a weakened exec approval binding in busybox and toybox on OpenClaw versions prior to 2026.4.12, which could allow attackers to elevate privileges.

    00000154
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more