Vulnerability
CVE-2026-100586
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 08:15
Description
OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capable turns with access to files, tools, and processes.
Aliases and classifications
CWE-269Improper Privilege Management
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 8.8
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- cvss severity
- HIGH
Provenance
Public references
- VulnCheck Advisory: OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind
https://www.vulncheck.com/advisories/openclaw-codex-before-2026.7.1-authorization-bypass-via-bind - GitHub Security Advisory (GHSA-9p6m-2872-xm7x)
https://github.com/openclaw/openclaw/security/advisories/GHSA-9p6m-2872-xm7x
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.