rootpwn

high · CVSS v3 8.3 · CVSS v4 8.7 · EPSS 0.0025

CVE-2026-100568

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible…

Description

OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.

Scores

Severity
high
CVSS v2
8.7
CVSS v3
8.3
CVSS v4
8.7
EPSS
0.0025

← All CVEs