Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-100580PATCHED
openclaw · openclaw

OpenClaw before 2026.7.1 Remote Code Execution via cron tool

Description

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool-enabled agent can therefore create a persistent cron job that executes attacker-selected commands with the privileges of the OpenClaw process user, resulting in access to host files and credentials and impact to scheduled service availability. The issue is limited to cron jobs created or edited through the model-facing cron tool; direct CLI and authorized Gateway scheduling surfaces are trusted operator controls. Fixed in 2026.7.1.

Affected Products

VendorProductVersions
openclawopenclaw0

References

  • https://github.com/openclaw/openclaw/security/advisories/GHSA-8xxh-v4vc-qvm4(vendor-advisory)
  • https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-remote-code-execution-via-cron-tool(third-party-advisory)

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-100580 | OpenClaw up to 2026.7.0 Cron Tool improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.7.1
CWECWE-178
PublishedSep 26, 2026
Last enriched1d ago
Trending Score22
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-100604EXP
ClawHub Authentication Bypass via Former Publisher Skill Control
Trending: 47
HIGHCVE-2026-100599EXP
OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
Trending: 36
HIGHCVE-2026-100589
OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
Trending: 23
HIGHCVE-2026-100597
OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
Trending: 23
HIGHCVE-2026-100596
OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 26, 2026
Discovered by ZDM
Sep 26, 2026
Patch Available
Sep 26, 2026